CVE-2022-31609
Last modified
CVE-2022-31609 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows the guest VM to allocate resources for which the guest is not authorized. This vulnerability may lead to loss of data integrity and confidentiality, denial of service, or information disclosure.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows the guest VM to allocate resources for which the guest is not authorized. This vulnerability may lead to loss of data integrity and confidentiality, denial of service, or information disclosure.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nvidia | Virtual Gpu | >= 11.0, < 11.8 |
| Nvidia | Virtual Gpu | >= 13.0, < 13.3 |
| Nvidia | Virtual Gpu | 14.0 |
| Nvidia | Virtual Gpu | 14.1 |
References
- https://nvidia.custhelp.com/app/answers/detail/a_id/5383Patch, Vendor Advisory
- https://nvidia.custhelp.com/app/answers/detail/a_id/5383Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-31609?
How severe is CVE-2022-31609?
How do I fix CVE-2022-31609?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-31603NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpS…6.7
- CVE-2022-31604NVFLARE, versions prior to 2.1.2, contains a vulnerability i…9.8
- CVE-2022-31605NVFLARE, versions prior to 2.1.2, contains a vulnerability i…9.8
- CVE-2022-31606NVIDIA GPU Display Driver for Windows contains a vulnerabili…7.8
- CVE-2022-31607NVIDIA GPU Display Driver for Linux contains a vulnerability…7.8
- CVE-2022-31608NVIDIA GPU Display Driver for Linux contains a vulnerability…7.8
- CVE-2022-3161 The APDFL.dll contains a memory corruption vulnerability w…7.8
- CVE-2022-31610NVIDIA GPU Display Driver for Windows contains a vulnerabili…7.8
- CVE-2022-31611 NVIDIA GeForce Experience contains an uncontrolled search p…7.3
- CVE-2022-31612NVIDIA GPU Display Driver for Windows contains a vulnerabili…7.1
- CVE-2022-31613NVIDIA GPU Display Driver for Windows contains a vulnerabili…6.5
- CVE-2022-31614NVIDIA vGPU software contains a vulnerability in the Virtual…7.8
Are you affected by CVE-2022-31609?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
