CVE-2024-0148CWE-447

NVIDIA Jetson Linux and IGX OS image contains a vulnerability in the UEFI firmware RCM boot mode, where an unprivileged attacker with physical access to the…

High · published February 25, 2025

CVSS v3.1
7.6
EPSS
0%
Percentile
21.1
In the wild
Unconfirmed
What it is

NVIDIA Jetson Linux and IGX OS image contains a vulnerability in the UEFI firmware RCM boot mode, where an unprivileged attacker with physical access to the device could load untrusted code. A successful exploit might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. The scope of the impacts can extend to other components.

The record
Technical detail
CVSS v3.1
7.6 · HIGH
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00289 · 21.1th percentile
Weakness
CWE-447 · Unimplemented or Unsupported Feature in UI
Published
2025-02-25T20:11Z
EPSS history
Timeline
  • 25 FEB 20:11Z
    NVIDIA Jetson Linux and IGX OS image contains a vulnerability in the UEFI firmware RCM boot mode, where an unprivileged attacker with physical access to the…
    cvelistv5