#VU48002 Arbitrary file upload in DGX-1 and AMI Baseboard Management Controller - CVE-2020-11486
Published: October 29, 2020 / Updated: October 29, 2020
DGX-1
AMI Baseboard Management Controller
nVidia
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file during file upload. A remote attacker can upload or transfer files that can be automatically processed within the product's environment, which may lead to remote code execution.