CVE-2021-23219

MEDIUMCVSS 4.1/10EPSS 0.20%

Last modified

CVE-2021-23219 is a medium-severity vulnerability rated 4.1/10 on the CVSS scale. NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to access protected information by identifying, exploiting, and loading vulnerable microcode. Such an attack may lead to information disclosure.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.

Description

NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to access protected information by identifying, exploiting, and loading vulnerable microcode. Such an attack may lead to information disclosure.

Metrics

CVSS 3.1
4.1/10

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.20%

10.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
NvidiaDgx-1 P100All versions
NvidiaDgx-1 V100All versions
NvidiaDgx-2All versions
NvidiaDgx Station A100All versions
NvidiaDrive ConstellationAll versions
NvidiaGeforce Gt 605All versions
NvidiaGeforce Gt 610All versions
NvidiaGeforce Gt 620All versions
NvidiaGeforce Gt 625All versions
NvidiaGeforce Gt 630All versions
NvidiaGeforce Gt 635All versions
NvidiaGeforce Gt 640All versions
NvidiaGeforce Gt 705All versions
NvidiaGeforce Gt 710All versions
NvidiaGeforce Gt 720All versions
NvidiaGeforce Gt 730All versions
NvidiaGeforce Gt 740All versions
NvidiaGeforce Gtx 1050All versions
NvidiaGeforce Gtx 1050 TiAll versions
NvidiaGeforce Gtx 1060All versions
NvidiaGeforce Gtx 1070All versions
NvidiaGeforce Gtx 1070 TiAll versions
NvidiaGeforce Gtx 1080All versions
NvidiaGeforce Gtx 1080 TiAll versions
NvidiaGeforce Gtx 1650All versions
NvidiaGeforce Gtx 1650 SuperAll versions
NvidiaGeforce Gtx 1660All versions
NvidiaGeforce Gtx 1660 SuperAll versions
NvidiaGeforce Gtx 1660 TiAll versions
NvidiaGeforce Gtx 645All versions
NvidiaGeforce Gtx 650All versions
NvidiaGeforce Gtx 650 TiAll versions
NvidiaGeforce Gtx 650 Ti BoostAll versions
NvidiaGeforce Gtx 660All versions
NvidiaGeforce Gtx 660 TiAll versions
NvidiaGeforce Gtx 670All versions
NvidiaGeforce Gtx 680All versions
NvidiaGeforce Gtx 690All versions
NvidiaGeforce Gtx 745All versions
NvidiaGeforce Gtx 750All versions
NvidiaGeforce Gtx 750 TiAll versions
NvidiaGeforce Gtx 760All versions
NvidiaGeforce Gtx 760 TiAll versions
NvidiaGeforce Gtx 770All versions
NvidiaGeforce Gtx 780All versions
NvidiaGeforce Gtx 780 TiAll versions
NvidiaGeforce Gtx 950All versions
NvidiaGeforce Gtx 960All versions
NvidiaGeforce Gtx 970All versions
NvidiaGeforce Gtx 980All versions

Showing 50 of 135 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-23219?
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to access protected information by identifying, exploiting, and loading vulnerable microcode. Such an attack may lead to information disclosure.
How severe is CVE-2021-23219?
CVE-2021-23219 has a CVSS score of 4.1/10 (MEDIUM severity). The EPSS model estimates a 0.20% probability of exploitation in the next 30 days.
How do I fix CVE-2021-23219?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-23219?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST