Lucene search

K
cvelistNvidiaCVELIST:CVE-2020-11487
HistoryOct 29, 2020 - 3:35 a.m.

CVE-2020-11487

2020-10-2903:35:31
nvidia
www.cve.org
nvidia dgx
servers
bmc firmware
vulnerability
rsa 1024
information disclosure

AI Score

7.7

Confidence

High

EPSS

0.002

Percentile

53.8%

NVIDIA DGX servers, DGX-1 with BMC firmware versions prior to 3.38.30. DGX-2 with BMC firmware versions prior to 1.06.06 and all DGX A100 Servers with all BMC firmware versions, contains a vulnerability in the AMI BMC firmware in which the use of a hard-coded RSA 1024 key with weak ciphers may lead to information disclosure.

CNA Affected

[
  {
    "product": "NVIDIA DGX Servers",
    "vendor": "NVIDIA",
    "versions": [
      {
        "status": "affected",
        "version": "All DGX-1 with BMC firmware versions prior to 3.38.30, all DGX-2 with BMC firmware versions prior to 1.06.06, all  DGX A100 with all BMC firmware version."
      }
    ]
  }
]

AI Score

7.7

Confidence

High

EPSS

0.002

Percentile

53.8%

Related for CVELIST:CVE-2020-11487