CVE-2021-34398

CWE-8293 documents3 sources
Severity
7.8HIGH
EPSS
0.0%
top 88.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 13
Latest updateMay 24

Description

NVIDIA DCGM, all versions prior to 2.2.9, contains a vulnerability in the DIAG module where any user can inject shared libraries into the DCGM server, which is usually running as root, which may lead to privilege escalation, total loss of confidentiality and integrity, and complete denial of service.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5nvidia/nvidia_data_center_gpu_manager_(dcgm)DCGM versions prior to 2.2.9

🔴Vulnerability Details

2
GHSA
GHSA-wwx8-c8jc-fh33: NVIDIA DCGM contains a vulnerability in the DIAG module where any user can inject shared libraries into the DCGM server, which is usually running as r2022-05-24
CVEList
CVE-2021-34398: NVIDIA DCGM, all versions prior to 22021-08-13