CVE Feed

    Dashboard / CVE / CVE-2022-42268

    CVE-2022-42268

    Omniverse Kit contains a vulnerability in the reference applications Create, Audio2Face, Isaac Sim, View, Code, and Machinima. These applications allow executable Python code to be embedded in Universal Scene Description (USD) files to customize all aspects of a scene. If a user opens a USD file that contains embedded Python code in one of these applications, the embedded Python code automatically runs with the privileges of the user who opened the file. As a result, an unprivileged remote attacker could craft a USD file containing malicious Python code and persuade a local user to open the file, which may lead to information disclosure, data tampering, and denial of service.

    Published:Jan 12, 2023
    Last Modified:Apr 8, 2025
    EPS:Jan 12, 2023
    EPSS Score:0.00367
    CVSS Score:7.8

    Affected Products

    Vendor
    Nvidia
    Product
    Nvidia Isaac Sim
    Vendor
    Nvidia
    Product
    Omniverse Audio2face
    Vendor
    Nvidia
    Product
    Omniverse Code
    Vendor
    Nvidia
    Product
    Omniverse Create
    Vendor
    Nvidia
    Product
    Omniverse Machinima
    Vendor
    Nvidia
    Product
    Omniverse View

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High