CVE-2021-34398
Last modified
CVE-2021-34398 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. NVIDIA DCGM, all versions prior to 2.2.9, contains a vulnerability in the DIAG module where any user can inject shared libraries into the DCGM server, which is usually running as root, which may lead to privilege escalation, total loss of confidentiality and integrity, and complete denial of service.. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
NVIDIA DCGM, all versions prior to 2.2.9, contains a vulnerability in the DIAG module where any user can inject shared libraries into the DCGM server, which is usually running as root, which may lead to privilege escalation, total loss of confidentiality and integrity, and complete denial of service.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nvidia | Data Center Gpu Manager | < 2.2.9 |
References
- https://nvidia.custhelp.com/app/answers/detail/a_id/5219Vendor Advisory
- https://nvidia.custhelp.com/app/answers/detail/a_id/5219Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-34398?
How severe is CVE-2021-34398?
How do I fix CVE-2021-34398?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-34392Trusty TLK contains a vulnerability in the NVIDIA TLK kernel…5.5
- CVE-2021-34393Trusty contains a vulnerability in TSEC TA which deserialize…4.4
- CVE-2021-34394Trusty contains a vulnerability in the NVIDIA OTE protocol t…6.7
- CVE-2021-34395Trusty TLK contains a vulnerability in its access permission…4.2
- CVE-2021-34396Bootloader contains a vulnerability in access permission set…2.3
- CVE-2021-34397Bootloader contains a vulnerability in NVIDIA MB2, which may…2.3
- CVE-2021-34399NVIDIA GPU and Tegra hardware contain a vulnerability in the…4.4
- CVE-2021-3440HP Print and Scan Doctor, an application within the HP Smart…7.8
- CVE-2021-34400NVIDIA GPU and Tegra hardware contain a vulnerability in the…4.4
- CVE-2021-34401NVIDIA Linux kernel distributions contain a vulnerability in…7.8
- CVE-2021-34402NVIDIA Tegra kernel driver contains a vulnerability in NVIDI…6.7
- CVE-2021-34403NVIDIA Linux distributions contain a vulnerability in nvmap …7.8
Are you affected by CVE-2021-34398?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
