CVE-2021-1062: High severity nvidia vgpu software vulnerability
Published Jan 8, 2021
·Updated
NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input data length is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).
Affected Software
6 affected components
Nvidia Virtual GPU Manager>=8.0<8.6
Nvidia Virtual GPU Manager>=11.0<11.3
Citrix Hypervisor
Nutanix Ahv
redhat Enterprise Linux Kernel-based Virtual Machine
VMware vSphere
Event History
Jan 8, 2021
CVE Published
via MITRE·03:05 PM
Data Sourced
via MITRE·03:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-1062?
CVE-2021-1062 is a vulnerability in the NVIDIA vGPU manager that allows for tampering of data or denial of service due to a lack of input data length validation.
2
What is the severity of CVE-2021-1062?
The severity of CVE-2021-1062 is high with a severity value of 7.1.
3
Which software is affected by CVE-2021-1062?
NVIDIA vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3) are affected by CVE-2021-1062.
4
How can CVE-2021-1062 be exploited?
CVE-2021-1062 can be exploited by manipulating input data length in the vGPU plugin of NVIDIA vGPU manager.
5
Is Citrix Hypervisor vulnerable to CVE-2021-1062?
No, Citrix Hypervisor is not vulnerable to CVE-2021-1062.