CVE-2021-1097
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it improperly validates the length field in a request from a guest. This flaw allows a malicious guest to send a length field that is inconsistent with the actual length of the input, which may lead to information disclosure, data tampering, or denial of service. This affects vGPU version 12.x (prior to 12.3), version 11.x (prior to 11.5) and version 8.x (prior 8.8).
El software NVIDIA vGPU contiene una vulnerabilidad en el Virtual GPU Manager (vGPU plugin), donde se comprueba inapropiadamente el campo de longitud en una petición de un huésped. Este fallo permite a un huésped malicioso enviar un campo de longitud que es inconsistente con la longitud real de la entrada, lo que puede conllevar a una divulgación de información, manipulación de datos o denegación de servicio. Esto afecta a las versiones 12.x de vGPU (anteriores a 12.3), versiones 11.x (anteriores a 11.5) y versiones 8.x (anteriores a 8.8)
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-11-12 CVE Reserved
- 2021-07-21 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://nvidia.custhelp.com/app/answers/detail/a_id/5211 | 2021-07-30 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nvidia Search vendor "Nvidia" | Virtual Gpu Search vendor "Nvidia" for product "Virtual Gpu" | >= 8.0 < 8.8 Search vendor "Nvidia" for product "Virtual Gpu" and version " >= 8.0 < 8.8" | - |
Affected
| ||||||
Nvidia Search vendor "Nvidia" | Virtual Gpu Search vendor "Nvidia" for product "Virtual Gpu" | >= 11.0 < 11.5 Search vendor "Nvidia" for product "Virtual Gpu" and version " >= 11.0 < 11.5" | - |
Affected
| ||||||
Nvidia Search vendor "Nvidia" | Virtual Gpu Search vendor "Nvidia" for product "Virtual Gpu" | >= 12.0 < 12.3 Search vendor "Nvidia" for product "Virtual Gpu" and version " >= 12.0 < 12.3" | - |
Affected
|