Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-1120


NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a string provided by the guest OS may not be properly null terminated. The guest OS or attacker has no ability to push content to the plugin through this vulnerability, which may lead to information disclosure, data tampering, unauthorized code execution, and denial of service.


Published

2021-10-29T20:15:08.917

Last Modified

2024-11-21T05:43:38.200

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.0 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-170
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nvidia virtual_gpu < 8.9 Yes
Application nvidia virtual_gpu < 11.6 Yes
Application nvidia virtual_gpu < 12.4 Yes
Application nvidia virtual_gpu < 13.1 Yes

References