PT-2021-13510 · Nvidia · Nvidia Vgpu

Published

2021-10-29

·

Updated

2021-11-02

·

CVE-2021-1120

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: NVIDIA vGPU software (affected versions not specified)
Description: The NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a string provided by the guest OS may not be properly null terminated. This issue may lead to information disclosure, data tampering, unauthorized code execution, and denial of service. The guest OS or attacker has no ability to push content to the plugin through this vulnerability.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-1120

Affected Products

Nvidia Vgpu