CVE-2022-31609
HIGHNVIDIA Virtual GPU Manager 11.0-11.8 - Improper Authorization
Title source: llmDescription
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows the guest VM to allocate resources for which the guest is not authorized. This vulnerability may lead to loss of data integrity and confidentiality, denial of service, or information disclosure.
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://nvidia.custhelp.com/app/answers/detail/a_id/5383
Scores
CVSS v3
7.8
EPSS
0.0004
EPSS Percentile
13.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-285
Status
published
Products (3)
nvidia/virtual_gpu
14.0
nvidia/virtual_gpu
14.1
nvidia/virtual_gpu
11.0 - 11.8
Published
Aug 05, 2022
Tracked Since
Feb 18, 2026