« Volver al listado

CVE-2024-0093

Estado: ModificadaMedia (5.5)—

NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not explicitly authorized to have access to that information. A successful exploit of this vulnerability might lead to information disclosure.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-0093",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-0093",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-19T17:01:41.169385Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@nvidia.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@nvidia.com",
      "affectedData": [
        {
          "vendor": "nvidia",
          "product": "vGPU software and Cloud Gaming",
          "versions": [
            {
              "status": "affected",
              "version": "All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-06-13T22:15:12.863",
  "references": [
    {
      "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@nvidia.com"
    },
    {
      "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5551",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@nvidia.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not explicitly authorized to have access to that information. A successful exploit of this vulnerability might lead to information disclosure."
    },
    {
      "lang": "es",
      "value": "El software NVIDIA GPU para Linux contiene una vulnerabilidad que puede exponer información confidencial a un actor que no está autorizado explícitamente para tener acceso a esa información. Una explotación exitosa de esta vulnerabilidad podría dar lugar a la divulgación de información."
    }
  ],
  "lastModified": "2026-06-17T06:52:46.173",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "44592EFE-8D69-4B7F-B089-A612B5217199",
              "versionEndExcluding": "13.11"
            },
            {
              "criteria": "cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5CBF021-7A5A-412A-BBC2-EB75C6343BB1",
              "versionEndExcluding": "16.6",
              "versionStartIncluding": "14.0"
            },
            {
              "criteria": "cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2DFC08A7-3121-4D8F-88A6-9304C173A439",
              "versionEndExcluding": "17.2",
              "versionStartIncluding": "17.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "019A2188-0877-45DE-8512-F0BF70DD179C"
            },
            {
              "criteria": "cpe:2.3:o:citrix:hypervisor:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F7AE5C32-E060-44BA-8C13-3D73204191EE"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_kernel-based_virtual_machine:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "06C8B1C5-6401-45F9-8D3E-47E32067F428"
            },
            {
              "criteria": "cpe:2.3:o:vmware:vsphere:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8E4A22C5-B3E1-4106-997C-D1C845F2C1EE"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nvidia:cloud_gaming:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "699C6D58-B26C-4F27-A1BD-A1A80E0D6A36",
              "versionEndExcluding": "555.52.04"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_kernel-based_virtual_machine:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "06C8B1C5-6401-45F9-8D3E-47E32067F428"
            },
            {
              "criteria": "cpe:2.3:o:vmware:vsphere:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8E4A22C5-B3E1-4106-997C-D1C845F2C1EE"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@nvidia.com"
}