Weak Encryption in NVIDIA Security Engine Affects Data Privacy
CVE-2017-6284
5.5MEDIUM
Summary
The NVIDIA Security Engine is exposed to a vulnerability that arises from a flaw in its Deterministic Random Bit Generator (DRBG). This issue occurs when the DRBG fails to adequately initialize and securely handle sensitive data, utilizing a weakened encryption mechanism. As a consequence, sensitive information may be inadequately protected, leading to potential data leakage. The nature of this vulnerability necessitates immediate attention to ensure the integrity and confidentiality of the data processed by the affected systems.
Affected Version(s)
SHIELD TV NA
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved