PT-2021-13510 · Nvidia · Nvidia Vgpu
Published
2021-10-29
·
Updated
2021-11-02
·
CVE-2021-1120
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
NVIDIA vGPU software (affected versions not specified)
Description:
The NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a string provided by the guest OS may not be properly null terminated. This issue may lead to information disclosure, data tampering, unauthorized code execution, and denial of service. The guest OS or attacker has no ability to push content to the plugin through this vulnerability.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nvidia Vgpu