CVE-2019-5672

CRITICAL

NVIDIA Jetson TX1 and TX2 < R28.3 - Information Disclosure via Default SSH Keys

Title source: llm
STIX 2.1

Description

NVIDIA Jetson TX1 and TX2 contain a vulnerability in the Linux for Tegra (L4T) operating system (on all versions prior to R28.3) where the Secure Shell (SSH) keys provided in the sample rootfs are not replaced by unique host keys after sample rootsfs generation and flashing, which may lead to information disclosure.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://nvidia.custhelp.com/app/answers/detail/a_id/4787

Scores

CVSS v3 9.1
EPSS 0.0028
EPSS Percentile 51.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-320
Status published
Products (2)
nvidia/jetson_tx1 < r28.3
nvidia/jetson_tx2 < r28.3
Published Apr 11, 2019
Tracked Since Feb 18, 2026