CVE-2019-5672
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/04/2019
Last modified:
25/04/2019
Description
NVIDIA Jetson TX1 and TX2 contain a vulnerability in the Linux for Tegra (L4T) operating system (on all versions prior to R28.3) where the Secure Shell (SSH) keys provided in the sample rootfs are not replaced by unique host keys after sample rootsfs generation and flashing, which may lead to information disclosure.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Base Score 2.0
6.40
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:nvidia:jetson_tx1:*:*:*:*:*:*:*:* | r28.3 (excluding) | |
cpe:2.3:a:nvidia:jetson_tx2:*:*:*:*:*:*:*:* | r28.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page