GPU VulnDB

Database/NVIDIA / GPU stack

DGX H100 BMC: improper input validation in the REST service allows privilege escalation and info disclosure

CVSS 6.1CVE-2023-31012NVIDIA / GPU stack+1 more CVEscurated

Impact

A high-privileged adjacent-network attacker can send malformed input to the DGX H100 BMC REST service and escalate privileges or disclose information. NVIDIA split this into 2 CVE ids (CVE-2023-31012, CVE-2023-31013) covering separate REST code paths, but the advisory gives no distinguishing detail: same CWE-20 class, same vector, same severity, one firmware fix.

Who can reach it

Network-adjacent BMC REST client

What to do

Flash DGX H100 BMC firmware 23.08.18 (or later) out-of-band from the NVIDIA Enterprise Support Portal; this single update closes both ids.

Also covers 1 CVE

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2023-31013

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.