CVE Database
/

CVE-2022-42268

Back to search

CVE-2022-42268

Published: Jan 12, 2023

Modified: Apr 8, 2025

PUBLISHED

CVSS v3.1

7.8

HIGH

Description

Omniverse Kit contains a vulnerability in the reference applications Create, Audio2Face, Isaac Sim, View, Code, and Machinima. These applications allow executable Python code to be embedded in Universal Scene Description (USD) files to customize all aspects of a scene. If a user opens a USD file that contains embedded Python code in one of these applications, the embedded Python code automatically runs with the privileges of the user who opened the file. As a result, an unprivileged remote attacker could craft a USD file containing malicious Python code and persuade a local user to open the file, which may lead to information disclosure, data tampering, and denial of service.

VendorProductVersions

NVIDIA

Omniverse Audio2Face

affected
All versions prior to 2022.2

NVIDIA

Omniverse Create

affected
All versions prior to 2022.3

NVIDIA

NVIDIA Isaac Sim

affected
All versions prior to 2022.2.0

NVIDIA

Omniverse Machinima

affected
All versions prior to 2022.3

NVIDIA

Omniverse Code

affected
All versions prior to 2022.3.0

NVIDIA

Omniverse View

affected
All versions prior to 2022.2.1

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now