Improper access control in nVidia SHIELD TV



Published: 2019-08-06 | Updated: 2019-08-07
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2019-5682
CWE-ID CWE-284
Exploitation vector Local
Public exploit N/A
Vulnerable software
Subscribe
SHIELD TV
Hardware solutions / Firmware

Vendor nVidia

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Improper access control

EUVDB-ID: #VU19970

Risk: Low

CVSSv3.1: 5.3 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-5682

CWE-ID: CWE-284 - Improper Access Control

Exploit availability: No

Description

The vulnerability allows a local attacker to gain unauthorized access to sensitive information.

The vulnerability exists due to improper access restrictions in the Games App where it improperly exports an Activity but does not properly restrict which applications can launch the Activity. A local authenticated attacker can gain unauthorized access to the application.

This vulnerability may lead to code execution or denial of service.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

SHIELD TV: before 8.0

External links

http://nvidia.custhelp.com/app/answers/detail/a_id/4804


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###