NVIDIA Jetson TX1 and TX2 contain a vulnerability in the Linux for Tegra (L4T) operating system (on all versions prior to R28.3) where the Secure Shell (SSH) keys provided in the sample rootfs are not replaced by unique host keys after sample rootsfs generation and flashing, which may lead to information disclosure.
📦
jetson_tx2
Vendor: nvidia
Actively Exploited
0
CISA KEV List
PoC / Exploits
1
Code Available
Total RCEs
9
Remote Access
Total CVEs
47
Total Indexed
Avg. EPSS
1.71%
Exploit Prob.
Security Vulnerability Index
Page 5 / 5
9.1
CVSS
Severity: CRITICAL
5.5
CVSS
CVE-2018-3639
Exploit Found
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
Severity: MEDIUM