Lucene search

K
nvidiaNvidiaNVIDIA:4704
HistoryOct 16, 2018 - 12:00 a.m.

Security Bulletin: NVIDIA SHIELD TV – October 2018

2018-10-1600:00:00
nvidia.custhelp.com
18

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

5.6

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

EPSS

0.975

Percentile

100.0%

NVIDIA has released a software security update for SHIELD TV. This update addresses issues that may lead to information disclosure or escalation of privileges. To protect your system, download and install this software update. Go to NVIDIA Product Security.

Details

This section summarizes the potential impact that this security update addresses. Descriptions use CWE™, and base scores and vectors follow CVSS V3 standards.

CVE Description Base Score Vector
CVE‑2017‑6289 NVIDIA SHIELD TV contains a vulnerability in the Tegra kernel driver which could enable a local malicious application to execute arbitrary code within the Trusted Execution Experience (TEE) and lead to escalation of privileges. 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE‑2017‑6293 NVIDIA SHIELD TV contains a vulnerability in the Tegra kernel driver which could enable a local malicious application to execute arbitrary code within the Tegra X1 TrustZone (TZ) and lead to escalation of privileges. 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE‑2017‑5715 NVIDIA SHIELD TV contains a vulnerability in the Tegra kernel driver which could enable a local malicious application to execute arbitrary code within the Trusted Little Kernel (TLK) and lead to information disclosure. 5.3 AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE‑2018‑6246 NVIDIA SHIELD TV contains a vulnerability in the Tegra kernel driver where a possible out-of-bounds write due to missing bounds checks could lead to escalation of privileges to the TrustZone (TZ) with system execution privileges needed. 5.3 AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

SHIELD TV includes the Android™ security updates up to the Android Security Patch level 2018-07-01. For more information about what is included in Android security patch levels, refer to the Android Security Bulletins.

The NVIDIA risk assessment is based on an average of risk across a diverse set of installed systems and may not represent the true risk of your local installation. NVIDIA recommends consulting a security or IT professional to evaluate the risk to your specific configuration.

Security Updates

The following table lists the software products and versions affected, and the updated versions that include this security update.

Download the updates from Settings>About>System update.

Software Product Operating System Affected Versions Updated Versions
SHIELD TV Android O SHIELD Experience 7.0 and earlier SHIELD Experience Upgrade 7.1

Notes

  • Affected versions include the versions listed and all earlier branches and releases.
  • If you are using an unsupported version or an earlier unsupported branch, upgrade to the latest supported version. To identify products that are no longer supported, contact NVIDIA Support.

Mitigations

None. See Security Updates for the versions to install.

Acknowledgements

None.

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

5.6

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

EPSS

0.975

Percentile

100.0%