First published: Mon Feb 14 2022(Updated: )
NVIDIA License System contains a vulnerability in the installation scripts for the DLS virtual appliance, where a user on a network after signing in to the portal can access other users’ credentials, allowing them to gain escalated privileges, resulting in limited impact to both confidentiality and integrity.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA License System | <1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-21818 has a limited impact on confidentiality due to the potential exposure of user credentials.
To mitigate CVE-2022-21818, update the NVIDIA License System to version 1.1 or later.
Users of the NVIDIA License System version prior to 1.1 are affected by CVE-2022-21818.
CVE-2022-21818 allows unauthorized access to other users' credentials due to weaknesses in the installation scripts.
Yes, CVE-2022-21818 represents an authentication issue as it involves accessing user credentials without proper authorization.