CVE-2023-31029: NVIDIA Dgx a100 Firmware

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

NVIDIA DGX A100 baseboard management controller (BMC) contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.

Affected products

  • NVIDIA Dgx a100 Firmware: before 00.22.05 (fixed in 00.22.05)

Published 2024-01-12. Last modified 2026-06-17.