Microcontroller Vulnerability in NVIDIA GPU and Tegra Hardware
CVE-2021-23219
4.1MEDIUM
Key Information:
- Vendor
- Nvidia
- Vendor
- CVE Published:
- 20 November 2021
Summary
NVIDIA GPU and Tegra hardware are impacted by a vulnerability in the internal microcontroller. This flaw potentially allows users with elevated privileges to identify, exploit, and load vulnerable microcode, leading to the unauthorized access of protected information. The implications of such an attack can result in information disclosure, which may compromise sensitive data handled by these devices.
Affected Version(s)
NVIDIA GPU and Tegra hardware Maxwell (except GM206), Tegra X1, Tegra X1+
References
CVSS V3.1
Score:
4.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved