IGX Orin bootloader: Improper access control in bootloader
CVSS 7.6CVE-2024-0148NVIDIA / GPU stackcurated
Impact
Improper access control in bootloader -> persistent compromise
Who can reach it
Local attacker with device access
What to do
Flash bootloader out-of-band
References
Related entries
- NeMo Framework: RCE via insecure deserializationCVE-2025-23249 · NeMo FrameworkHigh
- NeMo Framework: Arbitrary file write/read via path traversalCVE-2025-23250 · NeMo FrameworkHigh
- NeMo Framework: RCECVE-2025-23251 · NeMo FrameworkHigh
- Mellanox OFED: Authentication bypass in the host networking stackCVE-2025-23263 · Mellanox OFEDHigh
- NVIDIA NVDebug tool: NVDebug can be induced to write files into restricted components, reaching data tamperingCVE-2025-23343 · NVIDIA NVDebug toolHigh
- NVIDIA Jetson Linux (UEFI): UEFI accepts a Linux Device Tree without checking authorization, so anyone who reachesCVE-2025-33182 · NVIDIA Jetson Linux (UEFI)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.