CVE-2024-0148
NVIDIA Jetson Linux and IGX OS image contains a vulnerability in the UEFI firmware RCM boot mode, where an unprivileged attacker with physical access to the device could load untrusted code. A successful exploit might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. The scope of the impacts can extend to other components.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.6
- CVSS vector
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.29%
- CWE
- CWE-447
- Published
- 2025-02-25
- Last modified
- 2026-03-13
Affected products
- NVIDIA IGX Orin
- NVIDIA Jetson AGX Orin Series
Weakness type
Related vulnerabilities
- CVE-2024-39533 — Junos OS: QFX5000 Series and EX4600 Series: Output firewall filter is not applied if certain match criteria are used
- CVE-2024-21607 — Junos OS: MX Series and EX9200 Series: If the "tcp-reset" option used in an IPv6 filter, matched packets are accepted instead of rejected