CVE-2021-1099
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin) that could allow an attacker to cause stack-based buffer overflow and put a customized ROP gadget on the stack. Such an attack may lead to information disclosure, data tampering, or denial of service. This affects vGPU version 12.x (prior to 12.3), version 11.x (prior to 11.5) and version 8.x (prior 8.8).
El software NVIDIA vGPU contiene una vulnerabilidad en el Virtual GPU Manager (vGPU plugin) que podría permitir a un atacante causar un desbordamiento de búfer en la región stack de la memoria y poner un gadget ROP personalizado en la pila. Un ataque de este tipo podría conllevar a una divulgación de información, manipulación de datos o denegación de servicio. Esto afecta a las versiones 12.x de vGPU (anteriores a 12.3), versiones 11.x (anteriores a 11.5) y versiones 8.x (anteriores a 8.8)
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-11-12 CVE Reserved
- 2021-07-21 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://nvidia.custhelp.com/app/answers/detail/a_id/5211 | 2021-07-27 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nvidia Search vendor "Nvidia" | Virtual Gpu Search vendor "Nvidia" for product "Virtual Gpu" | >= 8.0 < 8.8 Search vendor "Nvidia" for product "Virtual Gpu" and version " >= 8.0 < 8.8" | - |
Affected
| ||||||
Nvidia Search vendor "Nvidia" | Virtual Gpu Search vendor "Nvidia" for product "Virtual Gpu" | >= 11.0 < 11.5 Search vendor "Nvidia" for product "Virtual Gpu" and version " >= 11.0 < 11.5" | - |
Affected
| ||||||
Nvidia Search vendor "Nvidia" | Virtual Gpu Search vendor "Nvidia" for product "Virtual Gpu" | >= 12.0 < 12.3 Search vendor "Nvidia" for product "Virtual Gpu" and version " >= 12.0 < 12.3" | - |
Affected
|