Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-5672


NVIDIA Jetson TX1 and TX2 contain a vulnerability in the Linux for Tegra (L4T) operating system (on all versions prior to R28.3) where the Secure Shell (SSH) keys provided in the sample rootfs are not replaced by unique host keys after sample rootsfs generation and flashing, which may lead to information disclosure.


Published

2019-04-11T17:29:01.320

Last Modified

2024-11-21T04:45:19.193

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 9.1 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-320

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nvidia jetson_tx1 < r28.3 Yes
Application nvidia jetson_tx2 < r28.3 Yes

References