Vulnerability Description
NVIDIA DCGM, all versions prior to 2.2.9, contains a vulnerability in the DIAG module where any user can inject shared libraries into the DCGM server, which is usually running as root, which may lead to privilege escalation, total loss of confidentiality and integrity, and complete denial of service.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nvidia | Data Center Gpu Manager | < 2.2.9 |
Related Weaknesses (CWE)
References
- https://nvidia.custhelp.com/app/answers/detail/a_id/5219Vendor Advisory
- https://nvidia.custhelp.com/app/answers/detail/a_id/5219Vendor Advisory
FAQ
What is CVE-2021-34398?
CVE-2021-34398 is a vulnerability with a CVSS score of 7.8 (HIGH). NVIDIA DCGM, all versions prior to 2.2.9, contains a vulnerability in the DIAG module where any user can inject shared libraries into the DCGM server, which is usually running as root, which may lead ...
How severe is CVE-2021-34398?
CVE-2021-34398 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-34398?
Check the references section above for vendor advisories and patch information. Affected products include: Nvidia Data Center Gpu Manager.