CVE-2024-0148
Published: 25 February 2025
Description
NVIDIA Jetson Linux and IGX OS image contains a vulnerability in the UEFI firmware RCM boot mode, where an unprivileged attacker with physical access to the device could load untrusted code. A successful exploit might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. The scope of the impacts can extend to other components.
Security Summary
CVE-2024-0148 affects the UEFI firmware RCM boot mode in NVIDIA Jetson Linux and IGX OS images. The vulnerability enables an unprivileged attacker with physical access to the device to load untrusted code, which could result in code execution, escalation of privileges, data tampering, denial of service, and information disclosure. Impacts may extend to other components. It carries a CVSS v3.1 base score of 7.6 (AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) and is linked to CWE-447.
Exploitation requires physical access to the device (AV:P) by an unprivileged attacker (PR:N) with low complexity (AC:L) and no user interaction (UI:N). Successful attacks can achieve high impacts on confidentiality, integrity, and availability, with a changed scope (S:C) potentially affecting additional components beyond the vulnerable one.
The NVIDIA security advisory provides details on mitigation and patching; refer to https://nvidia.custhelp.com/app/answers/detail/a_id/5617 for guidance.
Details
- CWE(s)