CVE-2021-1065: Input Validation
Published Jan 8, 2021
·Updated
NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which input data is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).
Affected Software
6 affected components
Nvidia Virtual GPU Manager>=8.0<8.6
Nvidia Virtual GPU Manager>=11.0<11.3
Citrix Hypervisor
Nutanix Ahv
redhat Enterprise Linux Kernel-based Virtual Machine
VMware vSphere
Event History
Jan 8, 2021
CVE Published
via MITRE·03:05 PM
Data Sourced
via MITRE·03:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-1065?
CVE-2021-1065 is a vulnerability in the NVIDIA vGPU manager, which allows for input data tampering or denial of service.
2
What versions of NVIDIA vGPU manager are affected by CVE-2021-1065?
NVIDIA vGPU manager version 8.x (prior to 8.6) and version 11.0 (prior to 11.3) are affected by CVE-2021-1065.
3
How severe is the vulnerability with CVE-2021-1065?
The severity of CVE-2021-1065 is high with a CVSS score of 7.1.
4
How can CVE-2021-1065 be exploited?
CVE-2021-1065 can be exploited by sending malicious input data to the vGPU plugin in the NVIDIA vGPU manager.
5
Is Citrix Hypervisor vulnerable to CVE-2021-1065?
No, Citrix Hypervisor is not vulnerable to CVE-2021-1065.