{"api_version":"1","generated_at":"2026-07-23T11:32:30+00:00","cve":"CVE-2019-5699","urls":{"html":"https://cve.report/CVE-2019-5699","api":"https://cve.report/api/cve/CVE-2019-5699.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-5699","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-5699"},"summary":{"title":"CVE-2019-5699","description":"NVIDIA Shield TV Experience prior to v8.0.1, NVIDIA Tegra bootloader contains a vulnerability where the software performs an incorrect bounds check, which may lead to buffer overflow resulting in escalation of privileges and code execution. escalation of privileges, and information disclosure, code execution, denial of service, or escalation of privileges.","state":"PUBLIC","assigner":"psirt@nvidia.com","published_at":"2019-10-09 22:15:00","updated_at":"2019-12-05 08:15:00"},"problem_types":["CWE-119"],"metrics":[],"references":[{"url":"https://nvidia.custhelp.com/app/answers/detail/a_id/4875","name":"https://nvidia.custhelp.com/app/answers/detail/a_id/4875","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Bulletin: NVIDIA SHIELD TV - October 2019 | NVIDIA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://nvidia.custhelp.com/app/answers/detail/a_id/4910","name":"https://nvidia.custhelp.com/app/answers/detail/a_id/4910","refsource":"CONFIRM","tags":[],"title":"Security Bulletin: Jetson AGX Xavier, TK1, TX1, TX2, and Nano L4T- December 2019 | NVIDIA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-5699","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-5699","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"5699","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"5699","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"5699","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nvidia","cpe5":"shield_experience","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"5699","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nvidia","cpe5":"shield_experience","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-5699","ASSIGNER":"psirt@nvidia.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"NVIDIA SHIELD TV","version":{"version_data":[{"version_value":"SHIELD Experience prior to v8.0.1"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"code execution, escalation of privileges"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://nvidia.custhelp.com/app/answers/detail/a_id/4875","url":"https://nvidia.custhelp.com/app/answers/detail/a_id/4875"},{"refsource":"CONFIRM","name":"https://nvidia.custhelp.com/app/answers/detail/a_id/4910","url":"https://nvidia.custhelp.com/app/answers/detail/a_id/4910"}]},"description":{"description_data":[{"lang":"eng","value":"NVIDIA Shield TV Experience prior to v8.0.1, NVIDIA Tegra bootloader contains a vulnerability where the software performs an incorrect bounds check, which may lead to buffer overflow resulting in escalation of privileges and code execution. escalation of privileges, and information disclosure, code execution, denial of service, or escalation of privileges."}]}},"nvd":{"publishedDate":"2019-10-09 22:15:00","lastModifiedDate":"2019-12-05 08:15:00","problem_types":["CWE-119"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":7.2},"severity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nvidia:shield_experience:*:*:*:*:*:*:*:*","versionEndExcluding":"8.0.1","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"5699","Ordinal":"143320","Title":"CVE-2019-5699","CVE":"CVE-2019-5699","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"5699","Ordinal":"1","NoteData":"NVIDIA Shield TV Experience prior to v8.0.1, NVIDIA Tegra bootloader contains a vulnerability where the software performs an incorrect bounds check, which may lead to buffer overflow resulting in escalation of privileges and code execution. escalation of privileges, and information disclosure, code execution, denial of service, or escalation of privileges.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"5699","Ordinal":"2","NoteData":"2019-10-09","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"5699","Ordinal":"3","NoteData":"2019-12-05","Type":"Other","Title":"Modified"}]}}}