Microcontroller Vulnerability in NVIDIA GPU and Tegra Hardware
CVE-2021-23219

4.1MEDIUM

Key Information:

Vendor
Nvidia
Vendor
CVE Published:
20 November 2021

Summary

NVIDIA GPU and Tegra hardware are impacted by a vulnerability in the internal microcontroller. This flaw potentially allows users with elevated privileges to identify, exploit, and load vulnerable microcode, leading to the unauthorized access of protected information. The implications of such an attack can result in information disclosure, which may compromise sensitive data handled by these devices.

Affected Version(s)

NVIDIA GPU and Tegra hardware Maxwell (except GM206), Tegra X1, Tegra X1+

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.