7.1
CVE-2023-0181
- EPSS 0.03%
- Veröffentlicht 01.04.2023 05:15:07
- Zuletzt bearbeitet 21.11.2024 07:36:41
- Quelle psirt@nvidia.com
- Teams Watchlist Login
- Unerledigt Login
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a kernel mode layer handler, where memory permissions are not correctly checked, which may lead to denial of service and data tampering.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nvidia ≫ Virtual Gpu Version < 11.12
Citrix ≫ Hypervisor Version-
Linux ≫ Linux Kernel Version-
Microsoft ≫ Windows Version-
Redhat ≫ Enterprise Linux Kernel-based Virtual Machine Version-
VMware ≫ Vsphere Version-
Linux ≫ Linux Kernel Version-
Microsoft ≫ Windows Version-
Redhat ≫ Enterprise Linux Kernel-based Virtual Machine Version-
VMware ≫ Vsphere Version-
Nvidia ≫ Virtual Gpu Version >= 13.0 < 13.7
Citrix ≫ Hypervisor Version-
Linux ≫ Linux Kernel Version-
Microsoft ≫ Windows Version-
Redhat ≫ Enterprise Linux Kernel-based Virtual Machine Version-
VMware ≫ Vsphere Version-
Linux ≫ Linux Kernel Version-
Microsoft ≫ Windows Version-
Redhat ≫ Enterprise Linux Kernel-based Virtual Machine Version-
VMware ≫ Vsphere Version-
Nvidia ≫ Virtual Gpu Version >= 15.0 < 15.2
Citrix ≫ Hypervisor Version-
Linux ≫ Linux Kernel Version-
Microsoft ≫ Windows Version-
Redhat ≫ Enterprise Linux Kernel-based Virtual Machine Version-
VMware ≫ Vsphere Version-
Linux ≫ Linux Kernel Version-
Microsoft ≫ Windows Version-
Redhat ≫ Enterprise Linux Kernel-based Virtual Machine Version-
VMware ≫ Vsphere Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.03% | 0.057 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
|
psirt@nvidia.com | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
CWE-280 Improper Handling of Insufficient Permissions or Privileges
The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.