USB-triggered Buffer Overflow Vulnerability in NV3P Bootloader

USB-triggered Buffer Overflow Vulnerability in NV3P Bootloader

CVE-2021-1111 · MEDIUM Severity

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H

Bootloader contains a vulnerability in the NV3P server where any user with physical access through USB can trigger an incorrect bounds check, which may lead to buffer overflow, resulting in limited information disclosure, limited data integrity, and denial of service across all components.

Learn more about our Cis Benchmark Audit For Server Software.