Memory Access Vulnerability in NVIDIA Jetson's CBoot Component
CVE-2023-25518
7.1HIGH
Key Information:
- Vendor
Nvidia
- Vendor
- CVE Published:
- 23 June 2023
What is CVE-2023-25518?
NVIDIA Jetson devices contain a vulnerability in the CBoot component resulting from improper initialization of the PCIe controller without IOMMU support. This weakness allows attackers with physical access to exploit the device by reading from and writing to arbitrary memory regions. Successful exploits could lead to severe consequences, including unauthorized code execution, denial of service, and potential information leaks that compromise data integrity.
Affected Version(s)
Jetson AGX Xavier series, Jetson Xavier NX All versions prior to 32.7.4