CVE-2022-42285CWE-1231

DGX A100 SBIOS contains a vulnerability in the Pre-EFI Initialization (PEI)phase, where a privileged user can disable SPI flash protection, which may lead to…

Medium · published January 13, 2023

CVSS v3.1
6.0
EPSS
0%
Percentile
4.8
In the wild
Unconfirmed
What it is

DGX A100 SBIOS contains a vulnerability in the Pre-EFI Initialization (PEI)phase, where a privileged user can disable SPI flash protection, which may lead to denial of service, escalation of privileges, or data tampering.

The record
Technical detail
CVSS v3.1
6.0 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00154 · 4.8th percentile
Weakness
CWE-1231 · Improper Prevention of Lock Bit Modification
Published
2023-01-13T01:48Z
EPSS history
Timeline
  • 13 JAN 01:48Z
    DGX A100 SBIOS contains a vulnerability in the Pre-EFI Initialization (PEI)phase, where a privileged user can disable SPI flash protection, which may lead to…
    cvelistv5