CVE-2024-0083 is a cross-site scripting (XSS) vulnerability in the UI of NVIDIA ChatRTX for Windows, allowing an attacker to run malicious scripts in users' browsers. This flaw could lead to code execution, denial of service, and information disclosure. With a CVSS score of 6.5 (MEDIUM), it has a network attack vector and low attack complexity, requiring no user interaction. While there is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, it has garnered some community discussion and media coverage, indicating awareness of the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.2.1CPE matchmatch criteria | cpe:2.3:a:nvidia:chatrtx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.