DGX H100 BMC (KVM daemon): Session token theft via timing side channel
CVSS 8.0CVE-2023-25529NVIDIA / GPU stackcurated
Impact
Session token theft via timing side channel
Who can reach it
Network-adjacent unauthenticated
What to do
Flash BMC 23.08.18; rotate BMC credentials
References
Related entries
- DGX H100 BMC (KVM): Code execution + privescCVE-2023-25530 · DGX H100 BMC (KVM)High
- Triton Inference Server: RCE / privesc via input-validation failureCVE-2025-23268 · Triton Inference ServerHigh
- Cumulus Linux / NVOS: Privesc to switch adminCVE-2025-33179 · Cumulus Linux / NVOSHigh
- Cumulus Linux / NVOS: Command injectionCVE-2025-33180 · Cumulus Linux / NVOSHigh
- NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmware: An attacker tampers with hardware controls directlyCVE-2025-33188 · NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmwareHigh
- NeMo Framework: Remote RCE via insecure deserialization over the networkCVE-2025-33245 · NeMo FrameworkHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.