CVE-2018-6242
Last modified
CVE-2018-6242 is a vulnerability of currently unknown severity. Some NVIDIA Tegra mobile processors released prior to 2016 contain a buffer overflow vulnerability in BootROM Recovery Mode (RCM). An attacker with physical access to the device's USB and the ability to force the device to reboot into RCM could exploit the vulnerability to execute unverified code.. EPSS estimates a 2.74% chance of exploitation in the next 30 days.
Description
Some NVIDIA Tegra mobile processors released prior to 2016 contain a buffer overflow vulnerability in BootROM Recovery Mode (RCM). An attacker with physical access to the device's USB and the ability to force the device to reboot into RCM could exploit the vulnerability to execute unverified code.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nvidia | Tegra Bootrom Rcm | All versions |
References
- http://nvidia.custhelp.com/app/answers/detail/a_id/4660Vendor Advisory
- http://nvidia.custhelp.com/app/answers/detail/a_id/4660Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-6242?
How severe is CVE-2018-6242?
How do I fix CVE-2018-6242?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-6235An Out-of-Bounds write privilege escalation vulnerability in…
- CVE-2018-6236A Time-of-Check Time-of-Use privilege escalation vulnerabili…
- CVE-2018-6237A vulnerability in Trend Micro Smart Protection Server (Stan…
- CVE-2018-6239NVIDIA Jetson TX2 contains a vulnerability by means of specu…
- CVE-2018-6240NVIDIA Tegra contains a vulnerability in BootRom where a use…
- CVE-2018-6241NVIDIA Tegra Gralloc module contains a vulnerability in driv…
- CVE-2018-6243NVIDIA Tegra TLK Widevine Trust Application contains a vulne…
- CVE-2018-6246In Android before the 2018-05-05 security patch level, NVIDI…
- CVE-2018-6247NVIDIA Windows GPU Display Driver contains a vulnerability i…
- CVE-2018-6248NVIDIA Windows GPU Display Driver contains a vulnerability i…
- CVE-2018-6249NVIDIA GPU Display Driver contains a vulnerability in kernel…
- CVE-2018-6250NVIDIA Windows GPU Display Driver contains a vulnerability i…
Are you affected by CVE-2018-6242?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
