CVE-2023-0209 is a high-severity vulnerability affecting the NVIDIA DGX-1 SBIOS, specifically within the Uncore PEI module. The flaw stems from a missing authentication mechanism for code executed by SSA, impacting NVIDIA DGX-1 and NVIDIA SBIOS products. With a CVSS score of 7.8 (High), this vulnerability allows for arbitrary code execution, denial of service, privilege escalation, information disclosure, data tampering, and SecureBoot bypass, all potentially assisted by a firmware implant. The attack vector is local, with low attack complexity and requiring low privileges. Currently, there is no evidence of active exploitation, nor are there any public exploit codes available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, aligning with the typical lack of attention for most vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 52w_3a13CPE matchmatch criteria | cpe:2.3:o:nvidia:sbios:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.