Skip to main content

CVE-2023-25531

7.6
HIGHCVSS v3.1 Base Score
0.23%
LOW RiskEPSS (46th percentile)

NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and escalation of privileges.

Published: 9/20/2023
Modified: 11/21/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.6HIGH

CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

0.23%LOW Exploitation Risk
46th percentile

This vulnerability has a 0.23% probability of being exploited in the next 30 days, ranking higher than 46% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-522)

CVE-2025-54863CRITICAL 10

Radiometrics VizAir is vulnerable to exposure of the system's REST API key through a publicly accessible configuration file. This allows attackers to remotely alter weather data and configurations, automate attacks against multiple instances, and extract sensitive meteorological data, which could potentially compromise airport operations. Additionally, attackers could flood the system with false alerts, leading to a denial-of-service condition and significant disruption to airport operations. Unauthorized remote control over aviation weather monitoring and data manipulation could result in incorrect flight planning and hazardous takeoff and landing conditions.

11/4/2025
CVE-2025-6519CRITICAL 9.8

E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably generate the password for ONEDAY. The oneday user cannot be deleted or modified by any user.

9/2/2025
CVE-2025-52549CRITICAL 9.8

E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can generate the root linux password for a vulnerable device based on known or easy to fetch parameters.

9/2/2025
CVE-2025-26492HIGH 7.7

In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources

2/11/2025
CVE-2025-0498CRITICAL 9.8

A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which could allow a threat actor to steal a token and, impersonate another user.

1/30/2025

Similar SeverityHIGH