Vulnerability Details CVE-2020-11616
NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which the Pseudo-Random Number Generator (PRNG) algorithm used in the JSOL package that implements the IPMI protocol is not cryptographically strong, which may lead to information disclosure.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 54.5%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2020-11616
-
-
cpe:2.3:o:intel:bmc_firmware:-
-
cpe:2.3:o:intel:bmc_firmware:1.06.06
-
cpe:2.3:o:intel:bmc_firmware:2.47