NVIDIA License System - DLS virtual appliance: Installation scripts on the DLS appliance leave other users' credentials
CVE-2022-21818NVIDIA / GPU stackcurated
Impact
Installation scripts on the DLS appliance leave other users' credentials readable to any signed-in portal user, giving lateral privilege escalation inside your licensing infrastructure.
Who can reach it
Network, authenticated as any portal user. Anyone you gave a licensing-portal account to.
What to do
Patch the DLS appliance per bulletin 5319 and rotate every credential the appliance held - the patch does not undo the exposure. Cost: appliance restart; vGPU guests keep running on cached licences through a short DLS outage.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.