CVE Database
/

CVE-2024-0148

Back to search

CVE-2024-0148

Published: Feb 25, 2025

Modified: Feb 25, 2025

PUBLISHED

CVSS v3.1

7.6

HIGH

Description

NVIDIA Jetson Linux and IGX OS image contains a vulnerability in the UEFI firmware RCM boot mode, where an unprivileged attacker with physical access to the device could load untrusted code. A successful exploit might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. The scope of the impacts can extend to other components.

VendorProductVersions

NVIDIA

IGX Orin

affected
All versions prior to IGX 1.1

NVIDIA

Jetson AGX Orin Series

affected
All versions prior to 36.4.3

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector

Physical

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now