« Volver al listado

CVE-2023-25517

Estado: ModificadaAlta (7.1)—

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest OS may be able to control resources for which it is not authorized, which may lead to information disclosure and data tampering.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-25517",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-25517",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-12-04T17:17:09.653475Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@nvidia.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@nvidia.com",
      "affectedData": [
        {
          "vendor": "NVIDIA",
          "product": "vGPU software",
          "versions": [
            {
              "status": "affected",
              "version": "All versions prior to and including 15.2, 13.7, and 11.12, and all versions prior to and including the May 2023 release"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-07-04T00:15:09.653",
  "references": [
    {
      "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5468",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@nvidia.com"
    },
    {
      "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5468",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@nvidia.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-285"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\nNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest OS may be able to control resources for which it is not authorized, which may lead to information disclosure and data tampering.\n\n"
    }
  ],
  "lastModified": "2026-06-17T05:41:24.057",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D1DC70BA-BE3C-4BCA-B24D-FC3CF0E35075",
              "versionEndExcluding": "11.13"
            },
            {
              "criteria": "cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9267A801-34DE-497D-AD10-5C65DE068955",
              "versionEndExcluding": "13.8",
              "versionStartIncluding": "13.0"
            },
            {
              "criteria": "cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6DCEAAB2-61CF-44E2-B251-732F43E980DF",
              "versionEndExcluding": "15.3",
              "versionStartIncluding": "15.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:citrix:hypervisor:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F7AE5C32-E060-44BA-8C13-3D73204191EE"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_kernel-based_virtual_machine:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "06C8B1C5-6401-45F9-8D3E-47E32067F428"
            },
            {
              "criteria": "cpe:2.3:o:vmware:vsphere:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8E4A22C5-B3E1-4106-997C-D1C845F2C1EE"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@nvidia.com"
}