Hopper HGX 8-GPU (HMC/firmware): Improper input validation in baseboard firmware
CVSS 8.1CVE-2024-0114NVIDIA / GPU stackcurated
Impact
Improper input validation in baseboard firmware -> code exec / tampering across the GPU baseboard
Who can reach it
Local privileged host access / mgmt path
What to do
Flash HGX baseboard firmware out-of-band; full node drain and power cycle
References
Related entries
- DGX Spark: Hardcoded credentials in configCVE-2026-24218 · DGX SparkHigh
- AI Tensor Engine for ROCm (AITER) - MessageQueue.recv() in shm_broadcast.py: AITER's MessageQueue.recv() deserialisesCVE-2026-49121 · AI Tensor Engine for ROCm (AITER) - MessageQueue.recv() in shm_broadcast.pyHigh
- DGX H100 BMC (KVM daemon): Session token theft via timing side channelCVE-2023-25529 · DGX H100 BMC (KVM daemon)High
- DGX H100 BMC (KVM): Code execution + privescCVE-2023-25530 · DGX H100 BMC (KVM)High
- Triton Inference Server: RCE / privesc via input-validation failureCVE-2025-23268 · Triton Inference ServerHigh
- Cumulus Linux / NVOS: Privesc to switch adminCVE-2025-33179 · Cumulus Linux / NVOSHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.