DGX H100 BMC (REST): Privesc via auth flaw
CVSS 6.6CVE-2023-31015NVIDIA / GPU stackcurated
Impact
Privesc via auth flaw
Who can reach it
Network-adjacent BMC REST client
What to do
Flash BMC 23.08.18 out-of-band
References
Related entries
- DGX H100 BMC: improper input validation in the REST service allows privilege escalation and info disclosureCVE-2023-31012 · DGX H100 BMC (REST)Medium
- DGX H100 BMC (REST): DoSCVE-2023-31011 · DGX H100 BMC (REST)Medium
- DGX H100 BMC (REST): Code execution + privescCVE-2023-31009 · DGX H100 BMC (REST)High
- DGX A100 SBIOS: Integer overflow in SBIOSCVE-2023-31034 · DGX A100 SBIOSMedium
- Linux kernel amdgpu power management (SMU/powerplay) (drm/amd): An out-of-bounds access in the amdgpu power managementCVE-2023-52819 · Linux kernel amdgpu power management (SMU/powerplay) (drm/amd)Medium
- NVIDIA Dynamo: Improper access control on privileged operationsCVE-2026-47619 · NVIDIA DynamoMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.