NVIDIA HGX & DGX GB200, GB300, B300 contain a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with administrative access on the BMC to access the HMC as an administrator. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://nvidia.custhelp.com/app/answers/detail/a_id/5692 |
![]() ![]() |
History
Thu, 18 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 18 Sep 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Nvidia
Nvidia dgx Nvidia dgx Gb200 Nvidia hgc Nvidia hgc B300 Nvidia hgx Nvidia hgx Gb300 |
|
Vendors & Products |
Nvidia
Nvidia dgx Nvidia dgx Gb200 Nvidia hgc Nvidia hgc B300 Nvidia hgx Nvidia hgx Gb300 |
Wed, 17 Sep 2025 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | NVIDIA HGX & DGX GB200, GB300, B300 contain a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with administrative access on the BMC to access the HMC as an administrator. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | |
Weaknesses | CWE-1244 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: nvidia
Published: 2025-09-17T22:27:15.541Z
Updated: 2025-09-19T03:55:11.737Z
Reserved: 2025-01-14T01:07:19.940Z
Link: CVE-2025-23337

Updated: 2025-09-18T13:29:48.680Z

Status : Awaiting Analysis
Published: 2025-09-17T23:15:36.500
Modified: 2025-09-18T13:43:34.310
Link: CVE-2025-23337

No data.