CVE-2021-34398

HIGH

Nvidia Data Center Gpu Manager < 2.2.9 - Denial of Service

Title source: rule
STIX 2.1

Description

NVIDIA DCGM, all versions prior to 2.2.9, contains a vulnerability in the DIAG module where any user can inject shared libraries into the DCGM server, which is usually running as root, which may lead to privilege escalation, total loss of confidentiality and integrity, and complete denial of service.

Scores

CVSS v3 7.8
EPSS 0.0004
EPSS Percentile 11.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-829
Status published
Products (1)
nvidia/data_center_gpu_manager < 2.2.9
Published Aug 13, 2021
Tracked Since Feb 18, 2026