CVE-2019-5672: Critical severity nvidia jetson tx1 l4t vulnerability
NVIDIA Jetson TX1 and TX2 contain a vulnerability in the Linux for Tegra (L4T) operating system (on all versions prior to R28.3) where the Secure Shell (SSH) keys provided in the sample rootfs are not replaced by unique host keys after sample rootsfs generation and flashing, which may lead to information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this NVIDIA Jetson TX1 and TX2 vulnerability?
The vulnerability ID for this NVIDIA Jetson TX1 and TX2 vulnerability is CVE-2019-5672.
What is the severity level of CVE-2019-5672?
The severity level of CVE-2019-5672 is critical with a severity value of 9.1.
What is affected by CVE-2019-5672?
NVIDIA Jetson TX1 and TX2 running Linux for Tegra (L4T) operating system versions prior to R28.3 are affected by CVE-2019-5672.
How does CVE-2019-5672 affect NVIDIA Jetson TX1 and TX2?
CVE-2019-5672 in NVIDIA Jetson TX1 and TX2 allows unauthorized access to the system through SSH due to the use of insecure default SSH keys.
How can I mitigate the vulnerability described in CVE-2019-5672?
To mitigate CVE-2019-5672, NVIDIA recommends generating and using unique SSH host keys on NVIDIA Jetson TX1 and TX2 devices.