CVE-2022-42289: NVIDIA Dgx a100 Firmware

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.

Affected products

  • NVIDIA Dgx a100 Firmware: before 00.19.07 (fixed in 00.19.07)

Published 2023-01-13. Last modified 2026-06-17.