Access Control Weakness in NVIDIA Jetson Products
CVE-2021-1070

7.1HIGH

Key Information:

Summary

NVIDIA's Jetson AGX Xavier series and related models have a vulnerability in the apply_binaries.sh script, which allows for improper access control during the installation of NVIDIA components. This flaw can enable unprivileged users to modify critical system device tree files, which may lead to a denial of service. Users should ensure that their systems are updated to L4T version 32.5 or later to mitigate this risk.

Affected Version(s)

NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano and Nano 2GB All L4T versions prior to r32.5

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.