Security News > 2021 > December > NVIDIA discloses applications impacted by Log4j vulnerability

NVIDIA discloses applications impacted by Log4j vulnerability
2021-12-22 15:42

NVIDIA has released a security advisory detailing what products are affected by the Log4Shell vulnerability that is currently exploited in a wide range of attacks worldwide.

vGPU Software License Server is impacted by CVE-2021-33228 and CVE-2021-45046 on versions 2021.07 and 2020.05 Update 1.

Finally, by default, DGX Systems does not come with the Log4j library, but NVIDIA warns that some users may have installed it themselves.

Even vulnerable internal applications need to be updated, as threat actors use the Log4Shell vulnerability to spread laterally within networks to deploy ransomware.

While unrelated to Log4j, NVIDIA has released a security update for the NVIDIA GeForce Experience software, addressing CVE-2021-23175.

Users can always source driver updates directly from the NVIDIA website and install them manually.


News URL

https://www.bleepingcomputer.com/news/security/nvidia-discloses-applications-impacted-by-log4j-vulnerability/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2021-12-23 CVE-2021-23175 Incorrect Authorization vulnerability in Nvidia Geforce Experience
NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls for users on the same device, which, with user intervention, may lead to escalation of privileges, information disclosure, data tampering, and denial of service, affecting other resources beyond the intended security authority of GameStream.
local
nvidia CWE-863
4.4
2021-12-14 CVE-2021-45046 Expression Language Injection vulnerability in multiple products
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations.
network
high complexity
apache intel siemens debian sonicwall fedoraproject CWE-917
critical
9.0

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Nvidia 278 80 209 222 16 527