Описание
NVIDIA GeForce Experience 3.x before GFE 3.1.0.52 contains a vulnerability in NVIDIA Web Helper.exe where a local web API endpoint, /VisualOPS/v.1.0./, lacks proper access control and parameter validation, allowing for information disclosure via a directory traversal attack.
Ссылки
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Not Applicable
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Not Applicable
Уязвимые конфигурации
Конфигурация 1Версия от 3.0 (включая) до 3.1.0.52 (исключая)
Одновременно
cpe:2.3:a:nvidia:geforce_experience:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
EPSS
Процентиль: 90%
0.05952
Низкий
6.5 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 6.5
github
больше 3 лет назад
NVIDIA GeForce Experience 3.x before GFE 3.1.0.52 contains a vulnerability in NVIDIA Web Helper.exe where a local web API endpoint, /VisualOPS/v.1.0./, lacks proper access control and parameter validation, allowing for information disclosure via a directory traversal attack.
EPSS
Процентиль: 90%
0.05952
Низкий
6.5 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-22