Learn about CVE-2021-1070 affecting NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano, Nano 2GB. Find details, impact, affected systems, mitigation, and prevention measures.
NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano and Nano 2GB devices with L4T versions prior to r32.5 are vulnerable to a denial of service attack due to improper access control in the apply_binaries.sh script.
Understanding CVE-2021-1070
This CVE affects NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano and Nano 2GB devices running L4T versions prior to r32.5, allowing an unprivileged user to modify system device tree files.
What is CVE-2021-1070?
CVE-2021-1070 is a vulnerability found in the apply_binaries.sh script used to install NVIDIA components into the root file system image. It results in improper access control, enabling an unprivileged user to disrupt device operation.
The Impact of CVE-2021-1070
The vulnerability poses a high risk, with a CVSS base score of 7.1 (High), impacting the system's integrity and availability. Successful exploitation could lead to a denial of service, potentially affecting the device's functionality.
Technical Details of CVE-2021-1070
This section provides more insights into the vulnerability.
Vulnerability Description
The vulnerability lies in the apply_binaries.sh script, lacking proper access controls, allowing unauthorized modification of system device tree files.
Affected Systems and Versions
Devices affected include NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano, and Nano 2GB with all L4T versions prior to r32.5.
Exploitation Mechanism
An attacker with low privileges can exploit this vulnerability locally, without requiring user interaction, leading to a denial of service attack.
Mitigation and Prevention
To address CVE-2021-1070, follow these mitigation measures.
Immediate Steps to Take
Ensure all NVIDIA Jetson devices are updated to L4T version r32.5 or newer to prevent exploitation of this vulnerability.
Long-Term Security Practices
Implement strict access controls and security policies to limit unauthorized access and modifications to critical system files.
Patching and Updates
Regularly check for updates and patches from NVIDIA to address security vulnerabilities and ensure the ongoing protection of your devices.