PT-2023-14071 · Nvidia · Omniverse Kit

Shashi Bhushan

·

Published

2023-01-12

·

Updated

2023-01-23

·

CVE-2022-42268

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Omniverse Kit (affected versions not specified)
Description The issue allows executable Python code to be embedded in Universal Scene Description (USD) files, which can be used to customize scenes in various applications, including Create, Audio2Face, Isaac Sim, View, Code, and Machinima. When a user opens a USD file containing embedded Python code, the code runs with the user's privileges. This could be exploited by an unprivileged remote attacker who crafts a USD file with malicious Python code, potentially leading to information disclosure, data tampering, and denial of service if a local user is persuaded to open the file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Special Elements Injection

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2022-42268

Affected Products

Omniverse Kit