Memory Access Vulnerability in NVIDIA Jetson's CBoot Component
CVE-2023-25518
7.1HIGH
Key Information:
- Vendor
Nvidia
- Vendor
- CVE Published:
- 23 June 2023
What is CVE-2023-25518?
NVIDIA Jetson devices contain a vulnerability in the CBoot component resulting from improper initialization of the PCIe controller without IOMMU support. This weakness allows attackers with physical access to exploit the device by reading from and writing to arbitrary memory regions. Successful exploits could lead to severe consequences, including unauthorized code execution, denial of service, and potential information leaks that compromise data integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jetson AGX Xavier series, Jetson Xavier NX All versions prior to 32.7.4
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved