Input validation error in IGX Orin and Jetson AGX Orin - CVE-2024-0112
Published: February 12, 2025
Vulnerability identifier: #VU103897
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-0112
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input. A local user can pass specially crafted input to the application and execute arbitrary code on the system.
Affected software
IGX Orin
Jetson AGX Orin
Jetson AGX Orin
How to mitigate CVE-2024-0112
Install updates from vendor's website.
IGX Orin - update to 1.1
Jetson AGX Orin - addressed in versions 35.6, 36.4.3
Jetson AGX Orin - addressed in versions 35.6, 36.4.3