CVE-2019-5680

MEDIUM

NVIDIA Jetson TX1 L4T < R32.2 - Code Execution via Unvalidated nvtboot-cpu Image Load

Title source: llm
STIX 2.1

Description

In NVIDIA Jetson TX1 L4T R32 version branch prior to R32.2, Tegra bootloader contains a vulnerability in nvtboot in which the nvtboot-cpu image is loaded without the load address first being validated, which may lead to code execution, denial of service, or escalation of privileges.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
https://nvidia.custhelp.com/app/answers/detail/a_id/4804
Vendor Advisory x_refsource_confirm
https://nvidia.custhelp.com/app/answers/detail/a_id/4835
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/109341

Scores

CVSS v3 6.7
EPSS 0.0007
EPSS Percentile 21.7%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (1)
nvidia/jetson_tx1_firmware < r32.2
Published Jul 19, 2019
Tracked Since Feb 18, 2026