CVE-2022-42287

NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary files under certain circumstances, which may lead to denial of service, escalation of privileges, information disclosure and data tampering.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nvidia:bmc:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:dgx_a100:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-01-13 04:15

Updated : 2024-11-21 07:24


NVD link : CVE-2022-42287

Mitre link : CVE-2022-42287

CVE.ORG link : CVE-2022-42287


JSON object : View

Products Affected

nvidia

  • bmc
  • dgx_a100
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-434

Unrestricted Upload of File with Dangerous Type