CVE-2019-5680: Input Validation
In NVIDIA Jetson TX1 L4T R32 version branch prior to R32.2, Tegra bootloader contains a vulnerability in nvtboot in which the nvtboot-cpu image is loaded without the load address first being validated, which may lead to code execution, denial of service, or escalation of privileges.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2019-5680.
What is the severity level of CVE-2019-5680?
The severity level of CVE-2019-5680 is medium with a severity value of 6.7.
What is the affected software for CVE-2019-5680?
The affected software for CVE-2019-5680 is Nvidia Jetson Tx1 Firmware version up to R32.2.
What is the potential impact of CVE-2019-5680?
The potential impact of CVE-2019-5680 includes code execution, denial of service, or escalation of privileges.
Where can I find more information about CVE-2019-5680?
You can find more information about CVE-2019-5680 at the following references: http://www.securityfocus.com/bid/109341, https://nvidia.custhelp.com/app/answers/detail/a_id/4804, https://nvidia.custhelp.com/app/answers/detail/a_id/4835