NVIDIA CUDA Toolkit
cpe:2.3:a:nvidia:cuda_toolkit:*:*:*:*:*:*:*
- < 13.1
A command injection vulnerability has been identified in NVIDIA Nsight Systems within the gfx_hotspot recipe. This issue allows an attacker to inject malicious strings into the process_nsys_rep_cli.py script, but only if the script is executed manually. Exploiting this vulnerability could result in unauthorized code execution, elevated privileges, data manipulation, service disruption, and unintended information exposure.
Successful exploitation could lead to arbitrary code execution, privilege escalation, unauthorized data modification, denial of service, and disclosure of sensitive information.
Users are advised to upgrade to the latest version of the NVIDIA CUDA Toolkit, available on the CUDA Toolkit Downloads page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.