AMD Instinct MI300X
cpe:2.3:h:amd:instinct_mi300x:*:*:*:*:*:*:*, +1 more
A denial-of-service vulnerability has been identified in the Satellite Management Controller (SMC) of AMD Instinct MI300X accelerators. This issue arises from improper input validation, which may allow an attacker with privileges to use certain special characters in manipulated Redfish API commands. Such manipulation can cause service processes, like OpenBMC, to crash and reset, leading to a potential denial-of-service condition.
Exploitation of this vulnerability can cause service processes to crash and reset, disrupting normal operations and potentially leading to a denial-of-service condition.
Users are advised to update AMD Instinct MI300X accelerators to version BKC 24.10 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.