CVE Vulnerabilities

CVE-2020-5964

Insufficient Verification of Data Authenticity

Published: Jun 25, 2020 | Modified: Jul 21, 2021
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the service host component, in which the application resources integrity check may be missed. Such an attack may lead to code execution, denial of service or information disclosure.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

Name Vendor Start Version End Version
Quadro_firmware Nvidia 390 (including) 392.61 (excluding)
Quadro_firmware Nvidia 418 (including) 426.78 (excluding)
Quadro_firmware Nvidia 440 (including) 443.18 (excluding)
Quadro_firmware Nvidia 450 (including) 451.48 (excluding)

References