7.1
CVE-2024-0128
- EPSS 0.07%
- Veröffentlicht 26.10.2024 09:15:03
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle psirt@nvidia.com
- CVE-Watchlists
- Unerledigt
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager that allows a user of the guest OS to access global resources. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and escalation of privileges.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstellernvidia
≫
Produkt
virtual_gpu_manager
Default Statusunaffected
Version
0
Version <
16.8
Status
affected
Version
17.0
Version <
17.4
Status
affected
Herstellernvidia
≫
Produkt
cloud_gaming_virtual_gpu
Default Statusunaffected
Version
0
Version <
565.57.01
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.215 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@nvidia.com | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
|
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.