CVE-2021-1071

NVIDIA Tegra kernel in Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano and Nano 2GB, all L4T versions prior to r32.5, contains a vulnerability in the INA3221 driver in which improper access control may lead to unauthorized users gaining access to system power usage data, which may lead to information disclosure.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nvidia:linux_for_tegra:*:*:*:*:*:*:*:*
OR cpe:2.3:h:nvidia:jetson_agx_xavier:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_nano:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_nano_2gb:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_tx1:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_tx2:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_xavier_nx:-:*:*:*:*:*:*:*

History

04 Feb 2021, 16:10

Type Values Removed Values Added
References (CONFIRM) https://nvidia.custhelp.com/app/answers/detail/a_id/5147 - (CONFIRM) https://nvidia.custhelp.com/app/answers/detail/a_id/5147 - Vendor Advisory
CWE NVD-CWE-Other
CPE cpe:2.3:h:nvidia:jetson_tx1:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_tx2:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_nano:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:linux_for_tegra:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_agx_xavier:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_nano_2gb:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_xavier_nx:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 2.1
v3 : 5.5

26 Jan 2021, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-01-26 22:15

Updated : 2023-12-10 13:41


NVD link : CVE-2021-1071

Mitre link : CVE-2021-1071

CVE.ORG link : CVE-2021-1071


JSON object : View

Products Affected

nvidia

  • jetson_agx_xavier
  • jetson_tx1
  • jetson_nano
  • jetson_nano_2gb
  • jetson_tx2
  • jetson_xavier_nx
  • linux_for_tegra