CVE-2020-5973 describes a denial-of-service vulnerability in the NVIDIA Virtual GPU Manager and guest drivers, specifically within the vGPU plugin, potentially allowing privileged operations. This affects NVIDIA vGPU versions 8.x (prior to 8.4), 9.x (prior to 9.4), and 10.x (prior to 10.3), as well as Canonical and NVIDIA Ubuntu Linux distributions utilizing these vGPU versions. The vulnerability has a CVSS score of 4.4 (Medium), indicating a local attack vector with low attack complexity, requiring high privileges, and resulting in high availability impact. There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0, <= 8.3CPE matchmatch criteria | cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:* | ||
>= 9.0, <= 9.3CPE matchmatch criteria | cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:* | ||
>= 10.0, <= 10.2CPE matchmatch criteria | cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* | ||
19.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.