Risk | Low |
Patch available | YES |
Number of vulnerabilities | 2 |
CVE-ID | CVE-2023-25518 CVE-2023-25520 |
CWE-ID | CWE-665 CWE-20 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software |
Jetson AGX Xavier series Hardware solutions / Firmware Jetson Xavier NX Hardware solutions / Firmware Jetson TX2 series Hardware solutions / Firmware Jetson TX2 NX Hardware solutions / Firmware |
Vendor | nVidia |
Security Bulletin
This security bulletin contains information about 2 vulnerabilities.
EUVDB-ID: #VU77724
Risk: Low
CVSSv3.1: 5.9 [CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-25518
CWE-ID:
CWE-665 - Improper Initialization
Exploit availability: No
DescriptionThe vulnerability allows an attacker to escalate privileges on the system.
The vulnerability exists due to improper initialization in CBoot. An attacker with physical access to device can read and write to arbitrary memory and execute arbitrary code on the system.
Install updates from vendor's website.
Vulnerable software versionsJetson AGX Xavier series: 32.1 - 32.7.3
Jetson Xavier NX: 32.1 - 32.7.3
CPE2.3http://nvidia.custhelp.com/app/answers/detail/a_id/5466
Q & A
Can this vulnerability be exploited remotely?
No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU77725
Risk: Low
CVSSv3.1: 6.2 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-25520
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in nvbootctrl within the NVIDIA Jetson Linux Driver Package. A local user can configure invalid settings and perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Vulnerable software versionsJetson AGX Xavier series: 32.1 - 32.7.3
Jetson Xavier NX: 32.1 - 32.7.3
Jetson TX2 series: 32.1 - 32.7.3
Jetson TX2 NX: 32.5.1 - 32.7.3
CPE2.3http://nvidia.custhelp.com/app/answers/detail/a_id/5466
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.