Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ppxx-pr9w-7ww8

Опубликовано: 25 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.6

Описание

NVIDIA Jetson Linux and IGX OS image contains a vulnerability in the UEFI firmware RCM boot mode, where an unprivileged attacker with physical access to the device could load untrusted code. A successful exploit might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. The scope of the impacts can extend to other components.

NVIDIA Jetson Linux and IGX OS image contains a vulnerability in the UEFI firmware RCM boot mode, where an unprivileged attacker with physical access to the device could load untrusted code. A successful exploit might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. The scope of the impacts can extend to other components.

EPSS

Процентиль: 21%
0.00067
Низкий

7.6 High

CVSS3

Дефекты

CWE-447

Связанные уязвимости

CVSS3: 7.6
nvd
12 месяцев назад

NVIDIA Jetson Linux and IGX OS image contains a vulnerability in the UEFI firmware RCM boot mode, where an unprivileged attacker with physical access to the device could load untrusted code. A successful exploit might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. The scope of the impacts can extend to other components.

CVSS3: 7.6
fstec
12 месяцев назад

Уязвимость загрузчика UEFI RCM программной платформы искусственного интеллекта промышленного класса NVIDIA IGX Orin и Jetson AGX Orin, позволяющая нарушителю выполнить произвольный код, вызвать отказ в обслуживании, раскрыть защищаемую информацию или повысить свои привилегии

EPSS

Процентиль: 21%
0.00067
Низкий

7.6 High

CVSS3

Дефекты

CWE-447