7.3

CVE-2021-1085

NVIDIA vGPU driver contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where there is the potential to write to a shared memory location and manipulate the data after the data has been validated, which may lead to denial of service and escalation of privileges and information disclosure but attacker doesn't have control over what information is obtained. This affects vGPU version 12.x (prior to 12.2), version 11.x (prior to 11.4) and version 8.x (prior to 8.7).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nvidia ≫ Virtual Gpu Manager Version >= 8.0 < 8.7
   Citrix ≫ Hypervisor Version -
   Nutanix ≫ Ahv Version -
   Redhat ≫ Enterprise Linux Kernel-based Virtual Machine Version -
   VMware ≫ Vsphere Version -
Nvidia ≫ Virtual Gpu Manager Version >= 11.0 < 11.4
   Citrix ≫ Hypervisor Version -
   Redhat ≫ Enterprise Linux Kernel-based Virtual Machine Version -
   VMware ≫ Vsphere Version -
Nvidia ≫ Virtual Gpu Manager Version >= 12.0 < 12.2
   Citrix ≫ Hypervisor Version -
   Redhat ≫ Enterprise Linux Kernel-based Virtual Machine Version -
   VMware ≫ Vsphere Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.149
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.3 1.8 5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
NIST 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
Nvidia 7.3 1.8 5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://nvidia.custhelp.com/app/answers/detail/a_id/5172
Vendor Advisory