Code Execution Risk in NVIDIA Jetson TX1 Tegra Bootloader
CVE-2019-5680
6.7MEDIUM
Summary
The NVIDIA Jetson TX1 has a critical flaw in its Tegra bootloader, specifically in the nvtboot component. This vulnerability arises from the nvtboot-cpu image being loaded without proper validation of its load address. Consequently, this oversight may result in unauthorized code execution, a denial of service, or unapproved privilege escalation, thereby posing significant security risks to users relying on this platform.
Affected Version(s)
NVIDIA Jetson TX1 R32 versions prior to 32.2
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved