CVE-2020-11616

NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which the Pseudo-Random Number Generator (PRNG) algorithm used in the JSOL package that implements the IPMI protocol is not cryptographically strong, which may lead to information disclosure.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:intel:bmc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:dgx-1:-:*:*:*:*:*:*:*

Information

Published : 2020-10-28 21:15

Updated : 2021-07-21 04:39


NVD link : CVE-2020-11616

Mitre link : CVE-2020-11616


JSON object : View

CWE
CWE-338

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

Advertisement

dedicated server usa

Products Affected

intel

  • bmc_firmware

nvidia

  • dgx-1