cbcvebase.
CVE-2022-21820
published 2022-03-24

CVE-2022-21820: NVIDIA DCGM contains a vulnerability in nvhostengine, where a network user can cause detection of error conditions without action, which may lead to limited…

PriorityP346medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
16.51%
96.6th percentile
NVIDIA DCGM contains a vulnerability in nvhostengine, where a network user can cause detection of error conditions without action, which may lead to limited code execution, some denial of service, escalation of privileges, and limited impacts to both data confidentiality and integrity.

Affected

2 ranges
VendorProductVersion rangeFixed in
nvidiadata_center_gpu_manager< 2.3.52.3.5
nvidianvidia_data_center_gpu_manager

CVSS provenance

nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.