CVE ID: CVE-2025-23337 Description: NVIDIA HGX & DGX GB200, GB300, B300 contain a vulnerability in the HMC Management Controller (HMC) that may allow a malicious actor with administrative access on the Baseboard Management Controller (BMC) to escalate privileges. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. Vector: AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Base Score: 8.7 Severity CWE: Medium Impacts: Code execution, denial of service, escalation of privileges, information disclosure, data tampering Affected Products: HGX & DGX (GB200, GB300, B300) Platform or OS: HGX HMC, DGX HMC and BMC Affected Versions: GB200 1.2, GB300 0.6 dev chip, B300 0.6 Updated Version: GB200 1.3, GB300 0.8, B300 0.6