Custom API Vulnerability in NVIDIA Shield TV Experience
CVE-2019-5681

7.8HIGH

Key Information:

Vendor
Nvidia
Status
Vendor
CVE Published:
13 August 2019

Summary

The NVIDIA Shield TV Experience prior to version 8.0 contains a vulnerability in its custom API used within the mount system service. This flaw allows for potential overruns of user data, which can be exploited to enable code execution, initiate denial of service attacks, or lead to unauthorized information disclosure.

Affected Version(s)

SHIELD TV SHIELD Experience prior to v8.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.