CRITICAL🇵🇱 Wersja polska

CVE-2019-5672

CVSS 9.1v3.0pub. 2019-04-11upd. 2024-11-21

NVIDIA Jetson TX1 and TX2 contain a vulnerability in the Linux for Tegra (L4T) operating system (on all versions prior to R28.3) where the Secure Shell (SSH) keys provided in the sample rootfs are not replaced by unique host keys after sample rootsfs generation and flashing, which may lead to information disclosure.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Nvidia Jetson Tx1

    APP
    Nvidia
    < r28.3
  • Nvidia Jetson Tx2

    APP
    Nvidia
    < r28.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2017-14491CRITICAL9.8PL ✓same product

Heap-based buffer overflow w dnsmasq umożliwiający RCE lub DoS

CVE-2024-0108HIGH8.7same product

NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail ...

CVE-2022-42269HIGH7.9same product

NVIDIA Trusted OS contains a vulnerability in an SMC call handler, where failure to validate untrusted input m...

CVE-2021-23201HIGH7.5same product

NVIDIA GPU and Tegra hardware contain a vulnerability in an internal microcontroller, which may allow a user w...

CVE-2021-23217HIGH7.5same product

NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user ...