First published: Sat Nov 20 2021(Updated: )
NVIDIA GPU and Tegra hardware contain a vulnerability in an internal microcontroller, which may allow a user with elevated privileges to generate valid microcode by identifying, exploiting, and loading vulnerable microcode. Such an attack could lead to information disclosure, data corruption, or denial of service of the device. The scope may extend to other components.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA GeForce GTX 950 | ||
NVIDIA GeForce GTX 960 | ||
NVIDIA GeForce GTX 970 | ||
NVIDIA GeForce GTX 980 | ||
NVIDIA GeForce GTX TITAN X | ||
NVIDIA Jetson Nano 2GB | ||
NVIDIA Jetson Nano 2GB | ||
NVIDIA Jetson Nano 2GB | ||
NVIDIA Jetson TX1 L4T | ||
Nvidia Quadro M1000M | ||
NVIDIA Quadro M1200 | ||
NVIDIA Quadro M2000 | ||
NVIDIA Quadro M2000M | ||
NVIDIA Quadro M2200 | ||
NVIDIA Quadro M3000M | ||
NVIDIA Quadro M4000 | ||
NVIDIA Quadro M4000M | ||
NVIDIA Quadro M5000 | ||
NVIDIA Quadro M5000M | ||
NVIDIA Quadro M500M | ||
NVIDIA Quadro M520 | ||
NVIDIA Quadro M5500 | ||
NVIDIA Quadro M6000 | ||
NVIDIA Quadro M600M | ||
NVIDIA Quadro M620 | ||
NVIDIA Shield TV | ||
NVIDIA Shield TV | ||
NVIDIA Tesla M10 | ||
NVIDIA Tesla M2050 | ||
NVIDIA Tesla M2070Q | ||
NVIDIA Tesla M2070Q | ||
NVIDIA Tesla M2090 | ||
NVIDIA Tesla M4 | ||
NVIDIA Tesla M40 | ||
NVIDIA Tesla M6 | ||
NVIDIA Tesla M60 | ||
Zero One Tech P100s | ||
Linux Kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23201 has a high severity rating due to the potential for information disclosure and data corruption.
To address CVE-2021-23201, users should update their NVIDIA drivers and firmware to the latest versions available.
CVE-2021-23201 affects various NVIDIA products, including the GeForce GTX series, Quadro series, and NVIDIA Shield TV.
Exploiting CVE-2021-23201 could allow an attacker with elevated privileges to load vulnerable microcode and compromise systems.
As of now, there is no known public exploit for CVE-2021-23201, but it's essential to remain vigilant and apply security updates.