CVE-2024-0148 Details
Description
NVIDIA Jetson Linux and IGX OS image contains a vulnerability in the UEFI firmware RCM boot mode, where an unprivileged attacker with physical access to the device could load untrusted code. A successful exploit might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. The scope of the impacts can extend to other components.
A vulnerability exists in the UEFI firmware RCM boot mode of NVIDIA Jetson Linux and IGX OS. This issue allows an unprivileged attacker with physical access to the device to load untrusted code. Exploitation of this vulnerability could result in unauthorized code execution, privilege escalation, data tampering, denial of service, and information disclosure, with potential impacts extending to other components.
Users are advised to upgrade to the latest version of the NVIDIA JetPack SDK for Jetson devices or to the new IGX Orin update from the IGX Download Center.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 25, 2025CISA-ADP
Assessed Feb 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://nvidia.custhelp.com/app/answers/detail/a_id/5617 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-447 | Unimplemented or Unsupported Feature in UI | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| NVIDIA IGX Orin | < 36.4.3 (semver) < 35.6 |
CPE
Remediation
| |
| NVIDIA Jetson AGX Orin | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 25, 2025 | New CVE Received | [email protected] |
Volerion