CVE-2025-23337
NVIDIA HGX & DGX GB200, GB300, B300 contain a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with administrative access on the BMC to access the HMC as an administrator. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.7
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.15%
- CWE
- CWE-1244
- Published
- 2025-09-17
- Last modified
- 2026-03-13
Affected products
- NVIDIA HGX GB200, HGX GB300, HGC B300
- NVIDIA DGX GB200, HGX GB300, HGC B300
Weakness type
Related vulnerabilities
- CVE-2026-8989 — Open Recovery Mode
- CVE-2025-67862 — An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244]...
- CVE-2025-36755 — CleverDisplay BlueOne unauthorized BIOS access through physical USB keyboard
- CVE-2025-42878 — Sensitive Data Exposure in SAP Web Dispatcher and Internet Communication Manager (ICM)
- CVE-2025-23302 — NVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the LS10 could enable an...
- CVE-2025-23301 — NVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the VBIOS could enable an...
- CVE-2025-20238 — A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco...
- CVE-2025-23252 — The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to...