CVE-2023-31031: NVIDIA Dgx a100 Firmware

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

NVIDIA DGX Station A100 and DGX Station A800 SBIOS contains a vulnerability where a user may cause a heap-based buffer overflow by local access. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and data tampering.

Affected products

  • NVIDIA Dgx a100 Firmware: before 1.25 (fixed in 1.25)

Published 2024-01-12. Last modified 2026-06-17.