Database/Firmware, BMC & network fabric
NVIDIA DGX BMC (AMI firmware): A hard-coded RSA-1024 key with weak ciphers in the BMC firmware means the encryption
Impact
A hard-coded RSA-1024 key with weak ciphers in the BMC firmware means the encryption protecting BMC sessions and data is decryptable by anyone holding the firmware image - so passively captured management traffic can be read. Notably this one lists all DGX A100 BMC firmware versions as affected, not just older DGX-1/DGX-2 builds.
Who can reach it
Anyone who can capture traffic on the management network, plus anyone who can download the firmware - which is everyone.
What to do
Flash the DGX BMC firmware from NVIDIA's DGX firmware update container (DGX-1 to 3.38.30 or later, DGX-2 to 1.06.06 or later; DGX A100 per the bulletin's table). A BMC flash does not require the host OS to reboot but drops out-of-band management for several minutes and NVIDIA recommends a host power cycle afterwards, so treat it as a per-node maintenance window. Rotate every BMC and IPMI credential after the flash - flashing does not invalidate secrets an attacker already pulled. Keep BMCs on an isolated management VLAN with no route from tenant or job networks.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.