CVE-2021-1111

Bootloader contains a vulnerability in the NV3P server where any user with physical access through USB can trigger an incorrect bounds check, which may lead to buffer overflow, resulting in limited information disclosure, limited data integrity, and denial of service across all components.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nvidia:jetson_linux:*:*:*:*:*:*:*:*
OR cpe:2.3:h:nvidia:jetson_agx_xavier:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_tx2:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_tx2_nx:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_xavier_nx:-:*:*:*:*:*:*:*

History

08 Jul 2022, 18:54

Type Values Removed Values Added
CWE CWE-119 CWE-125

25 Jan 2022, 18:31

Type Values Removed Values Added
CVSS v2 : 3.6
v3 : 3.5
v2 : 4.6
v3 : 6.7

25 Jan 2022, 11:15

Type Values Removed Values Added
Summary Bootloader contains a vulnerability in the NV3P server where any user with physical access through USB can trigger an incorrect bounds check, which may lead to buffer overflow, resulting in limited information disclosure, limited data integrity, and information disclosure across all components. Bootloader contains a vulnerability in the NV3P server where any user with physical access through USB can trigger an incorrect bounds check, which may lead to buffer overflow, resulting in limited information disclosure, limited data integrity, and denial of service across all components.

20 Aug 2021, 15:01

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 3.6
v3 : 3.5
References (MISC) https://nvidia.custhelp.com/app/answers/detail/a_id/5216 - (MISC) https://nvidia.custhelp.com/app/answers/detail/a_id/5216 - Vendor Advisory
CPE cpe:2.3:h:nvidia:jetson_agx_xavier:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:jetson_linux:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_tx2_nx:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_tx2:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_xavier_nx:-:*:*:*:*:*:*:*
CWE CWE-119

11 Aug 2021, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-08-11 22:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-1111

Mitre link : CVE-2021-1111

CVE.ORG link : CVE-2021-1111


JSON object : View

Products Affected

nvidia

  • jetson_agx_xavier
  • jetson_xavier_nx
  • jetson_tx2
  • jetson_linux
  • jetson_tx2_nx
CWE
CWE-125

Out-of-bounds Read

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer