{"cve":{"cve_id":"CVE-2022-42287","is_kev":false,"kev_date_added":null,"kev_vendor_project":null,"kev_product":null,"kev_vulnerability_name":null,"kev_short_description":null,"kev_required_action":null,"kev_due_date":null,"kev_known_ransomware":null,"kev_notes":null,"kev_cwes":null,"epss_score":0.0022,"epss_percentile":0.1231,"epss_as_of":"2026-06-23","description":"NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary files under certain circumstances, which may lead to denial of service, escalation of privileges, information disclosure and data tampering.","published_at":"2023-01-13T02:07:42.144000Z","last_modified_at":null,"cvss_v3_score":6.0,"cvss_v3_vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","cvss_v3_severity":"MEDIUM","cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":"none","ssvc_automatable":false,"ssvc_technical_impact":"total","cwes":["CWE-22"],"nvd_references":["https://nvidia.custhelp.com/app/answers/detail/a_id/5435"],"vuln_status":null,"trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:39.878444Z","updated_at":"2026-06-29T01:20:09.065395Z"},"effective_severity":"MEDIUM","badges":[],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"L","value_label":"Local"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"PR","name":"Privileges Required","value":"H","value_label":"High"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"S","name":"Scope","value":"U","value_label":"Unchanged"},{"metric":"C","name":"Confidentiality","value":"H","value_label":"High"},{"metric":"I","name":"Integrity","value":"H","value_label":"High"},{"metric":"A","name":"Availability","value":"N","value_label":"None"}]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"nvidia","vendor_name":"NVIDIA","product_slug":"nvidia-dgx-servers","product_name":"NVIDIA DGX servers","version_start":"All BMC firmware versions prior to 00.19.07","version_start_inclusive":true,"version_end":"All BMC firmware versions prior to 00.19.07","version_end_inclusive":true,"cpe23_uri":"cve5:nvidia:nvidia-dgx-servers:All BMC firmware versions prior to 00.19.07:All BMC firmware versions prior to 00.19.07"}],"exploit_refs":[],"news":[],"references":[{"url":"https://nvidia.custhelp.com/app/answers/detail/a_id/5435","source_type":"MISC","tags":[]}],"timeline":[{"type":"published","at":"2023-01-13T02:07:42.144000Z","label":"CVE published","source":null},{"type":"cvss_changed","at":"2026-06-28T17:24:02.830174Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:24:02.830174Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:24:02.830174Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"ssvc_changed","at":"2026-06-29T01:20:09.065395Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-29T01:20:09.065395Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-29T01:20:09.065395Z","label":"SSVC decision revised","source":"vulnrichment"}]}