CVE-2022-42285CWE-1231
DGX A100 SBIOS contains a vulnerability in the Pre-EFI Initialization (PEI)phase, where a privileged user can disable SPI flash protection, which may lead to…
Medium · published January 13, 2023
What it is
DGX A100 SBIOS contains a vulnerability in the Pre-EFI Initialization (PEI)phase, where a privileged user can disable SPI flash protection, which may lead to denial of service, escalation of privileges, or data tampering.
The record
Technical detail
- CVSS v3.1
- 6.0 · MEDIUM
- Vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
- CVSS v4.0
- Not supplied
- EPSS
- 0.00154 · 4.8th percentile
- Weakness
- CWE-1231 · Improper Prevention of Lock Bit Modification
- Published
- 2023-01-13T01:48Z
EPSS history
Timeline