DGX A100 BMC: unauthenticated stack overflow in the host KVM daemon leads to RCE
Impact
An unauthenticated attacker who can reach the BMC network interface can corrupt stack memory in the host KVM daemon with a crafted packet, leading to arbitrary code execution on the BMC, denial of service, information disclosure and data tampering. NVIDIA split this one KVM-daemon stack-corruption class across 2 CVE ids in security bulletin 5510; there is no separate action for either id.
Who can reach it
Network-adjacent mgmt-LAN attacker
What to do
Flash DGX A100 BMC firmware 00.22.05 or later out-of-band, and keep the BMC on an isolated management VLAN unreachable from tenant or general networks.
Also covers 1 CVE
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- DGX A100 BMC: Missing authentication on BMC serviceCVE-2023-31033 · DGX A100 BMCMedium
- DGX A100 BMC: LDAP injection in BMC authCVE-2023-31025 · DGX A100 BMCMedium
- DGX A100 BMC: Full BMC compromise (heap buffer overflow) — worst-case out-of-band takeoverCVE-2023-31029 · DGX A100 BMCCritical
- Base Command Manager (CMDaemon): Unauthenticated RCE on the cluster managerCVE-2024-0138 · Base Command Manager (CMDaemon)Critical
- NVIDIA Isaac Launchable: Hard-coded credentials in Isaac Launchable give an unauthenticated network attacker codeCVE-2025-33222 · NVIDIA Isaac LaunchableCritical
- NVIDIA Isaac Launchable: Execution with unnecessary privileges lets an unauthenticated network attacker reach codeCVE-2025-33223 · NVIDIA Isaac LaunchableCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.