Deserialization Vulnerability in TSEC TA by NVIDIA
CVE-2021-34393
4.2MEDIUM
Key Information:
- Vendor
- Nvidia
- Vendor
- CVE Published:
- 22 June 2021
Summary
NVIDIA's TSEC TA is affected by a vulnerability that arises from improper handling of deserialized incoming messages. Although TSEC TA does not expose any commands, the flaw allows attackers to exploit the deserialization process, potentially leading to unauthorized code execution and information disclosure. This interaction poses a significant risk to system integrity and confidentiality, highlighting the importance of securing software components against such vulnerabilities.
Affected Version(s)
NVIDIA Jetson TX2 series, TX2 NX, AGX Xavier series, Xavier NX All Jetson Linux versions prior to r32.5.1
References
CVSS V3.1
Score:
4.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved