Lucene search

K
cve[email protected]CVE-2021-1070
HistoryJan 26, 2021 - 10:15 p.m.

CVE-2021-1070

2021-01-2622:15:12
web.nvd.nist.gov
39
4
cve-2021-1070
nvidia
jetson
agx xavier
xavier nx
tx1
tx2
nano
nano 2gb
l4t
access control
denial of service

3.6 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

7.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

7.1 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.8%

NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano and Nano 2GB, L4T versions prior to 32.5, contains a vulnerability in the apply_binaries.sh script used to install NVIDIA components into the root file system image, in which improper access control is applied, which may lead to an unprivileged user being able to modify system device tree files, leading to denial of service.

Affected configurations

NVD
Node
nvidiajetson_agx_xavierMatch-
OR
nvidiajetson_nanoMatch-
OR
nvidiajetson_nano_2gbMatch-
OR
nvidiajetson_tx1Match-
OR
nvidiajetson_tx2Match-
OR
nvidiajetson_xavier_nxMatch-
AND
nvidialinux_for_tegraRange<r32.5

CNA Affected

[
  {
    "product": "NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano and Nano 2GB",
    "vendor": "NVIDIA",
    "versions": [
      {
        "status": "affected",
        "version": "All L4T versions prior to r32.5"
      }
    ]
  }
]

Social References

More

3.6 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

7.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

7.1 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.8%

Related for CVE-2021-1070