NVIDIA Jetson Linux and IGX OS UEFI Firmware Vulnerability Allowing Unprivileged Code Execution

Vulnerability

A vulnerability exists in the UEFI firmware RCM boot mode of NVIDIA Jetson Linux and IGX OS. This issue allows an unprivileged attacker with physical access to the device to load untrusted code. Exploitation of this vulnerability could result in unauthorized code execution, privilege escalation, data tampering, denial of service, and information disclosure, with potential impacts extending to other components.

Impact

Successful exploitation could lead to code execution, privilege escalation, data corruption, denial of service, and information disclosure.

Remediation

Users are advised to upgrade to the latest version of the NVIDIA JetPack SDK for Jetson devices or to the new IGX Orin update from the IGX Download Center.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
7.5
exploitability
3.5
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.