First published: Fri Jul 19 2019(Updated: )
In NVIDIA Jetson TX1 L4T R32 version branch prior to R32.2, Tegra bootloader contains a vulnerability in nvtboot in which the nvtboot-cpu image is loaded without the load address first being validated, which may lead to code execution, denial of service, or escalation of privileges.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nvidia Jetson Tx1 Firmware | <r32.2 | |
NVIDIA Jetson TX1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-5680.
The severity level of CVE-2019-5680 is medium with a severity value of 6.7.
The affected software for CVE-2019-5680 is Nvidia Jetson Tx1 Firmware version up to R32.2.
The potential impact of CVE-2019-5680 includes code execution, denial of service, or escalation of privileges.
You can find more information about CVE-2019-5680 at the following references: http://www.securityfocus.com/bid/109341, https://nvidia.custhelp.com/app/answers/detail/a_id/4804, https://nvidia.custhelp.com/app/answers/detail/a_id/4835