« Volver al listado

CVE-2021-39158

Estado: ModificadaAlta (8.8)—

La lista de dependencias requeridas de python de NVCaffe solía contener la versión "gfortran" anterior a 0.17.4, entrada que no se presenta en el repositorio pypi.org. Un atacante podría potencialmente haber publicado archivos maliciosos en pypi.org causando que un usuario lo instale dentro de NVCaffe.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-39158",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "NVIDIA",
          "product": "caffe",
          "versions": [
            {
              "status": "affected",
              "version": "<= 0.17.4"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-08-23T21:15:09.643",
  "references": [
    {
      "url": "https://github.com/NVIDIA/caffe/security/advisories/GHSA-fmpp-8pwg-vwh9",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/NVIDIA/caffe/security/advisories/GHSA-fmpp-8pwg-vwh9",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-345"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "NVCaffe's python required dependencies list used to contain `gfortran`version prior to 0.17.4, entry which does not exist in the repository pypi.org. An attacker could potentially have posted malicious files to pypi.org causing a user to install it within NVCaffe."
    },
    {
      "lang": "es",
      "value": "La lista de dependencias requeridas de python de NVCaffe solía contener la versión \"gfortran\" anterior a 0.17.4, entrada que no se presenta en el repositorio pypi.org. Un atacante podría potencialmente haber publicado archivos maliciosos en pypi.org causando que un usuario lo instale dentro de NVCaffe."
    }
  ],
  "lastModified": "2026-06-17T04:03:12.990",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nvidia:nvcaffe:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "09948C78-23E5-475D-8151-DFC40A25A222",
              "versionEndExcluding": "0.17.4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}