CVE-2021-23201
Last modified
CVE-2021-23201 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. NVIDIA GPU and Tegra hardware contain a vulnerability in an internal microcontroller, which may allow a user with elevated privileges to generate valid microcode by identifying, exploiting, and loading vulnerable microcode. Such an attack could lead to information disclosure, data corruption, or denial of service of the device. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
NVIDIA GPU and Tegra hardware contain a vulnerability in an internal microcontroller, which may allow a user with elevated privileges to generate valid microcode by identifying, exploiting, and loading vulnerable microcode. Such an attack could lead to information disclosure, data corruption, or denial of service of the device. The scope may extend to other components.
Metrics
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nvidia | Geforce Gtx 950 | All versions |
| Nvidia | Geforce Gtx 960 | All versions |
| Nvidia | Geforce Gtx 970 | All versions |
| Nvidia | Geforce Gtx 980 | All versions |
| Nvidia | Geforce Gtx Titan X | All versions |
| Nvidia | Jetson Nano | All versions |
| Nvidia | Jetson Tx1 | All versions |
| Nvidia | Quadro M1000m | All versions |
| Nvidia | Quadro M1200 | All versions |
| Nvidia | Quadro M2000 | All versions |
| Nvidia | Quadro M2000m | All versions |
| Nvidia | Quadro M2200 | All versions |
| Nvidia | Quadro M3000m | All versions |
| Nvidia | Quadro M4000 | All versions |
| Nvidia | Quadro M4000m | All versions |
| Nvidia | Quadro M5000 | All versions |
| Nvidia | Quadro M5000m | All versions |
| Nvidia | Quadro M500m | All versions |
| Nvidia | Quadro M520 | All versions |
| Nvidia | Quadro M5500 | All versions |
| Nvidia | Quadro M6000 | All versions |
| Nvidia | Quadro M600m | All versions |
| Nvidia | Quadro M620 | All versions |
| Nvidia | Shield Tv | All versions |
| Nvidia | Shield Tv Pro | All versions |
| Nvidia | Tesla M10 | All versions |
| Nvidia | Tesla M2050 | All versions |
| Nvidia | Tesla M2070 | All versions |
| Nvidia | Tesla M2070q | All versions |
| Nvidia | Tesla M2090 | All versions |
| Nvidia | Tesla M4 | All versions |
| Nvidia | Tesla M40 | All versions |
| Nvidia | Tesla M6 | All versions |
| Nvidia | Tesla M60 | All versions |
| Nvidia | Tesla P100 | All versions |
References
- https://nvidia.custhelp.com/app/answers/detail/a_id/5263Vendor Advisory
- https://nvidia.custhelp.com/app/answers/detail/a_id/5263Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-23201?
How severe is CVE-2021-23201?
How do I fix CVE-2021-23201?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-23195Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard)…5.3
- CVE-2021-23196The web application on Agilia Link+ version 3.0 implements a…9.8
- CVE-2021-23197Unquoted service path vulnerability in the Gallagher Control…7.8
- CVE-2021-23198mySCADA myPRO: Versions 8.20.0 and prior has a feature where…9.8
- CVE-2021-23199Rejected reason: This candidate was in a CNA pool that was n…
- CVE-2021-2320Vulnerability in the Oracle Cloud Infrastructure Storage Gat…9.1
- CVE-2021-23203Improper access control in reporting engine of Odoo Communit…7.5
- CVE-2021-23204Exposure of Sensitive Information to an Unauthorized Actor v…6.5
- CVE-2021-23205Improper Encoding or Escaping in Gallagher Command Centre Se…8.1
- CVE-2021-23206A flaw was found in htmldoc in v1.9.12 and prior. A stack bu…7.8
- CVE-2021-23207An attacker with physical access to the host can extract the…5.5
- CVE-2021-23209Multiple Authenticated (admin user role) Persistent Cross-Si…4.8
Are you affected by CVE-2021-23201?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
