VULNERABILITY INTELLIGENCE
CVE-2017-6284
CVSS score5.5 MEDIUM
EPSS probability0.07%
CISA KEVNot currently listed
Published2018-03-06
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Description
NVIDIA Security Engine contains a vulnerability in the Deterministic Random Bit Generator (DRBG) where the DRBG does not properly initialize and store or transmits sensitive data using a weakened encryption scheme that is unable to protect sensitive data which may lead to information disclosure.This issue is rated as moderate.
Weakness classification
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-326: Inadequate Encryption Strength
Primary references
- psirt@nvidia.com — Vendor Advisory
- psirt@nvidia.com
- af854a3a-2127-422b-91ae-364da2661108 — Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108