CVE-2022-21820
medium · 6.3NVIDIA DCGM contains a vulnerability in nvhostengine, where a network user can cause detection of error conditions without action, which may lead to limited code execution, some denial of service, escalation of privileges, and limited impacts to both data confidentiality and integrity.
6.3
CVSS
16.5%
EPSS (exploit prob.)
97th
EPSS percentile
2022-03-24
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Weaknesses
CWE-20CWE-755CWE-787
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| nvidia | data_center_gpu_manager | < 2.3.5 |
| linux | linux_kernel | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/167396/NVIDIA-Data-Center-GPU-Manager-Remote-Memory-Corruption.html
- https://nvidia.custhelp.com/app/answers/detail/a_id/5328
- http://packetstormsecurity.com/files/167396/NVIDIA-Data-Center-GPU-Manager-Remote-Memory-Corruption.html
- https://nvidia.custhelp.com/app/answers/detail/a_id/5328
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-21820