Memory Access Vulnerability in NVIDIA Jetson's CBoot Component
CVE-2023-25518
7.1HIGH
Key Information:
- Vendor
- Nvidia
- Vendor
- CVE Published:
- 23 June 2023
Summary
NVIDIA Jetson devices contain a vulnerability in the CBoot component resulting from improper initialization of the PCIe controller without IOMMU support. This weakness allows attackers with physical access to exploit the device by reading from and writing to arbitrary memory regions. Successful exploits could lead to severe consequences, including unauthorized code execution, denial of service, and potential information leaks that compromise data integrity.
Affected Version(s)
Jetson AGX Xavier series, Jetson Xavier NX All versions prior to 32.7.4
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved