Nvidia has addressed 11 vulnerabilities in the firmware of its DGX A100 AI system, with three ranked critical due to their potential for remote code execution. These flaws reside in the keyboard, video, and mouse (KVM) daemon within the baseboard management controller (BMC).
Users of the DGX A100, a five petaFLOPS AI machine powered by A100 Tensor cores, are urged to update their BMC firmware to version 00.22.05 or later to mitigate these critical vulnerabilities (CVE-2023-31029, CVE-2023-31030, and CVE-2023-31024). Exploiting these flaws could allow attackers to remotely run malicious code, potentially leading to data theft, system crashes, or unauthorized access.
Additional Vulnerabilities
Two further vulnerabilities (CVE-2023-25529 and CVE-2023-25530) were also identified in the KVM service of the BMCs in the DGX H100 and DGX A100 systems. CVE-2023-25529 could expose a user’s session token, while CVE-2023-25530 involves an input validation issue. Updating to BMC firmware version 00.22.05 addresses these vulnerabilities as well.
Nvidia has also released fixes for lesser-severity vulnerabilities in DGX A100 SBIOS versions prior to 1.25. Applying this update is recommended for additional security hardening even if your system isn’t affected by the critical BMC vulnerabilities.
While Nvidia has issued patches, it’s crucial to remain vigilant. Regularly update your systems and monitor security advisories to stay ahead of potential threats.
Key Takeaways:
- Critical vulnerabilities found in Nvidia DGX A100 BMC KVM daemon.
- Remote code execution, data theft, and system crashes possible.
- Update BMC firmware to version 00.22.05 or later.
- Additional vulnerabilities in DGX H100 and A100 BMCs addressed.
- Update DGX A100 SBIOS if necessary.
- Maintain security vigilance and update systems regularly.

