Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-5977

Опубликовано: 23 окт. 2020
Источник: nvd
CVSS3: 7.8
CVSS2: 4.4
EPSS Низкий

Описание

NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in NVIDIA Web Helper NodeJS Web Server in which an uncontrolled search path is used to load a node module, which may lead to code execution, denial of service, escalation of privileges, and information disclosure.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nvidia:geforce_experience:*:*:*:*:*:*:*:*
Версия до 3.20.5.70 (исключая)

EPSS

Процентиль: 23%
0.00075
Низкий

7.8 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-426

Связанные уязвимости

github
больше 3 лет назад

NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in NVIDIA Web Helper NodeJS Web Server in which an uncontrolled search path is used to load a node module, which may lead to code execution, denial of service, escalation of privileges, and information disclosure.

EPSS

Процентиль: 23%
0.00075
Низкий

7.8 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-426