#VU48007 Cryptographic issues in DGX-1 and AMI Baseboard Management Controller - CVE-2020-11616
Published: October 29, 2020 / Updated: October 29, 2020
DGX-1
AMI Baseboard Management Controller
nVidia
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the Pseudo-Random Number Generator (PRNG) algorithm used in the JSOL package that implements the IPMI protocol is not cryptographically strong. A remote attacker on the local network can gain unauthorized access to sensitive information on the system.