Back to Database
Status published
High
CVE-2023-25507
NVIDIA DGX-1 BMC contains a vulnerability in the SPX REST...
Vulnerability Description
NVIDIA DGX-1 BMC contains a vulnerability in the SPX REST API, where an attacker with the appropriate level of authorization can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure, and data tampering.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-25507
Credits & Attribution
No credits recorded in the NVD database.
More from NVIDIA
View All →CVE-2025-33255
NVIDIA TRT-LLM for any platform contains a vulnerability in MPI...
High
7.5
CVE-2025-33254
NVIDIA Triton Inference Server contains a vulnerability where an attacker...
High
7.5
CVE-2025-33253
NVIDIA NeMo Framework contains a vulnerability where an attacker could...
High
7.8
CVE-2025-33252
NVIDIA NeMo Framework contains a vulnerability where an attacker could...
High
7.8
CVE-2025-33251
NVIDIA NeMo Framework contains a vulnerability where an attacker could...
High
7.8
Affected Vendor
NVIDIA
View all reports →Affected Software
NVIDIA DGX servers
Vulnerable Versions:
All BMC versions prior to 3.39.3
Timeline
Official Publish:
April 22nd, 2023
Last Modified:
February 4th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H