Deserialization Vulnerability in TSEC TA by NVIDIA
CVE-2021-34393

4.2MEDIUM

Key Information:

Summary

NVIDIA's TSEC TA is affected by a vulnerability that arises from improper handling of deserialized incoming messages. Although TSEC TA does not expose any commands, the flaw allows attackers to exploit the deserialization process, potentially leading to unauthorized code execution and information disclosure. This interaction poses a significant risk to system integrity and confidentiality, highlighting the importance of securing software components against such vulnerabilities.

Affected Version(s)

NVIDIA Jetson TX2 series, TX2 NX, AGX Xavier series, Xavier NX All Jetson Linux versions prior to r32.5.1

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.