CVE-2020-5985: Input Validation
Published Oct 2, 2020
·Updated
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data length is not validated, which may lead to tampering or denial of service. This affects vGPU version 8.x (prior to 8.5), version 10.x (prior to 10.4) and version 11.0.
Affected Software
3 affected components
Nvidia Virtual GPU Manager>=8.0<8.5
Nvidia Virtual GPU Manager>=10.0<10.4
Nvidia Virtual GPU Manager=11.0
Event History
Oct 2, 2020
CVE Published
via MITRE·09:10 PM
Data Sourced
via MITRE·09:10 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this NVIDIA Virtual GPU Manager vulnerability?
The vulnerability ID for this NVIDIA Virtual GPU Manager vulnerability is CVE-2020-5985.
2
What is the severity of CVE-2020-5985?
The severity of CVE-2020-5985 is high with a CVSS score of 7.1.
3
Which versions of vGPU are affected by this vulnerability?
This vulnerability affects vGPU version 8.x (prior to 8.5), version 10.x (prior to 10.4), and version 11.0.
4
What is the impact of this vulnerability?
This vulnerability in NVIDIA Virtual GPU Manager may lead to tampering or denial of service.
5
How can I fix the vulnerability in NVIDIA Virtual GPU Manager?
To fix the vulnerability, upgrade to vGPU version 8.5 or later, version 10.4 or later, or version 11.0 of NVIDIA Virtual GPU Manager.