Security News > 2021 > December > NVIDIA discloses applications impacted by Log4j vulnerability
NVIDIA has released a security advisory detailing what products are affected by the Log4Shell vulnerability that is currently exploited in a wide range of attacks worldwide.
vGPU Software License Server is impacted by CVE-2021-33228 and CVE-2021-45046 on versions 2021.07 and 2020.05 Update 1.
Finally, by default, DGX Systems does not come with the Log4j library, but NVIDIA warns that some users may have installed it themselves.
Even vulnerable internal applications need to be updated, as threat actors use the Log4Shell vulnerability to spread laterally within networks to deploy ransomware.
While unrelated to Log4j, NVIDIA has released a security update for the NVIDIA GeForce Experience software, addressing CVE-2021-23175.
Users can always source driver updates directly from the NVIDIA website and install them manually.
News URL
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-12-23 | CVE-2021-23175 | Incorrect Authorization vulnerability in Nvidia Geforce Experience NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls for users on the same device, which, with user intervention, may lead to escalation of privileges, information disclosure, data tampering, and denial of service, affecting other resources beyond the intended security authority of GameStream. | 4.4 |
2021-12-14 | CVE-2021-45046 | Expression Language Injection vulnerability in multiple products It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. | 9.0 |