« Volver al listado

CVE-2022-31609

Estado: ModificadaAlta (7.8)—

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows the guest VM to allocate resources for which the guest is not authorized. This vulnerability may lead to loss of data integrity and confidentiality, denial of service, or information disclosure.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-31609",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-31609",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-02T14:19:41.315907Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@nvidia.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@nvidia.com",
      "affectedData": [
        {
          "vendor": "NVIDIA",
          "product": "NVIDIA Virtual GPU Software and NVIDIA Cloud Gaming",
          "versions": [
            {
              "status": "affected",
              "version": "vGPU version 14.x (prior to 14.2), version 13.x (prior to 13.4) and version 11.x (prior 11.9)."
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-08-05T21:15:08.813",
  "references": [
    {
      "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5383",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "psirt@nvidia.com"
    },
    {
      "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5383",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@nvidia.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-285"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows the guest VM to allocate resources for which the guest is not authorized. This vulnerability may lead to loss of data integrity and confidentiality, denial of service, or information disclosure."
    },
    {
      "lang": "es",
      "value": "El software NVIDIA vGPU contiene una vulnerabilidad en el Virtual GPU Manager (vGPU plugin), donde permite que la VM invitada asigne recursos para los que el invitado no está autorizado. Esta vulnerabilidad puede conllevar a una pérdida de integridad y confidencialidad de los datos, una denegación de servicio o una divulgación de información"
    }
  ],
  "lastModified": "2026-06-17T04:45:46.940",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "45F338C5-245D-4D10-9B48-B56B7094F167",
              "versionEndExcluding": "11.8",
              "versionStartIncluding": "11.0"
            },
            {
              "criteria": "cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "98C8F13F-2F8F-4BAE-B971-582084B93D58",
              "versionEndExcluding": "13.3",
              "versionStartIncluding": "13.0"
            },
            {
              "criteria": "cpe:2.3:a:nvidia:virtual_gpu:14.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3CB2F728-3BFD-418D-AC29-A4165D1E7CA6"
            },
            {
              "criteria": "cpe:2.3:a:nvidia:virtual_gpu:14.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F3C0C0B2-C4DC-4DB8-BD80-D6082FD1248B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@nvidia.com"
}