Lucene search

K
cvelistNvidiaCVELIST:CVE-2020-11485
HistoryOct 29, 2020 - 3:35 a.m.

CVE-2020-11485

2020-10-2903:35:30
nvidia
www.cve.org
3
nvidia dgx servers
csrf vulnerability
bmc firmware
information disclosure
code execution

AI Score

9.1

Confidence

High

EPSS

0.001

Percentile

31.0%

NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a Cross-Site Request Forgery (CSRF) vulnerability in the AMI BMC firmware in which the web application does not sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request, which can lead to information disclosure or code execution.

CNA Affected

[
  {
    "product": "NVIDIA DGX Servers",
    "vendor": "NVIDIA",
    "versions": [
      {
        "status": "affected",
        "version": "All DGX-1 Servers with BMC firmware versions prior to 3.38.30"
      }
    ]
  }
]

AI Score

9.1

Confidence

High

EPSS

0.001

Percentile

31.0%

Related for CVELIST:CVE-2020-11485