DGX A100 BMC: Full BMC compromise (heap buffer overflow) — worst-case out-of-band takeover
CVSS 10.0CVE-2023-31029NVIDIA / GPU stackcurated
Impact
Full BMC compromise (heap buffer overflow) — worst-case out-of-band takeover
Who can reach it
Network-adjacent unauthenticated on mgmt LAN
What to do
Emergency: flash BMC 00.22.05+ out-of-band, audit BMC logs for compromise, rotate all mgmt credentials
References
Related entries
- DGX A100 BMC: unauthenticated stack overflow in the host KVM daemon leads to RCECVE-2023-31024 · DGX A100 BMCCritical
- DGX A100 BMC: Missing authentication on BMC serviceCVE-2023-31033 · DGX A100 BMCMedium
- DGX A100 BMC: LDAP injection in BMC authCVE-2023-31025 · DGX A100 BMCMedium
- Univa Grid Engine (execd spooling with Docker jobs on root_squash): In the specific combination of Docker-based jobsCVE-2018-20871 · Univa Grid Engine (execd spooling with Docker jobs on root_squash)Critical
- NVIDIA Windows GPU Display Driver, DirectX driver (shader compiler/runtime): A crafted shader overruns a shader-localCVE-2019-5685 · NVIDIA Windows GPU Display Driver, DirectX driver (shader compiler/runtime)Critical
- RISC-V ISA (MTVEC register) as used in NVIDIA GPU microcontrollers: A documented ambiguity in the RISC-V specificationCVE-2021-1104 · RISC-V ISA (MTVEC register) as used in NVIDIA GPU microcontrollersCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.