CVE-2022-28199 is a high-severity vulnerability in NVIDIA's Data Plane Development Kit (MLNX_DPDK) network stack, stemming from improper error recovery. This flaw primarily affects NVIDIA, Linux, and Microsoft distributions of DPDK, as well as the Linux kernel and Windows operating systems. With a CVSS score of 8.6, it can be exploited remotely without authentication, potentially leading to denial of service and some impact on data integrity and confidentiality. While there are no known public exploits or Metasploit modules, the vulnerability has garnered minimal community discussion and limited media coverage, with no indication of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 19.11_1.0.0, < 20.11_5.0.0CPE matchmatch criteria | cpe:2.3:a:nvidia:data_plane_development_kit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.