CVE-2024-0148 is a high-severity vulnerability in the UEFI firmware RCM boot mode of NVIDIA Jetson Linux and IGX OS images, allowing an unprivileged attacker with physical access to load untrusted code. This could lead to code execution, privilege escalation, data tampering, denial of service, and information disclosure, with potential impacts extending to other system components. While the CVSS score is 7.6 (HIGH), indicating a significant risk, there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| NVIDIA | IGX Orin | All versions prior to IGX 1.1CNA affecteddefault unaffected | |
| NVIDIA | Jetson AGX Orin Series | All versions prior to 36.4.3CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.