CVE-2024-0148
Last modified
CVE-2024-0148 is a high-severity vulnerability rated 7.6/10 on the CVSS scale. NVIDIA Jetson Linux and IGX OS image contains a vulnerability in the UEFI firmware RCM boot mode, where an unprivileged attacker with physical access to the device could load untrusted code. A successful exploit might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
NVIDIA Jetson Linux and IGX OS image contains a vulnerability in the UEFI firmware RCM boot mode, where an unprivileged attacker with physical access to the device could load untrusted code. A successful exploit might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. The scope of the impacts can extend to other components.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-0148?
How severe is CVE-2024-0148?
How do I fix CVE-2024-0148?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-0142NVIDIA nvJPEG2000 library contains a vulnerability where an …6.8
- CVE-2024-0143NVIDIA nvJPEG2000 library contains a vulnerability where an …6.8
- CVE-2024-0144NVIDIA nvJPEG2000 library contains a vulnerability where an …6.8
- CVE-2024-0145NVIDIA nvJPEG2000 library contains a vulnerability where an …6.8
- CVE-2024-0146NVIDIA vGPU software contains a vulnerability in the Virtual…7.8
- CVE-2024-0147NVIDIA GPU display driver for Windows and Linux contains a v…5.5
- CVE-2024-0149NVIDIA GPU Display Driver for Linux contains a vulnerability…3.3
- CVE-2024-0150NVIDIA GPU display driver for Windows and Linux contains a v…7.1
- CVE-2024-0151Insufficient argument checking in Secure state Entry functio…6.5
- CVE-2024-0153Improper Restriction of Operations within the Bounds of a Me…7.8
- CVE-2024-0154Dell PowerEdge Server BIOS and Dell Precision Rack BIOS cont…3.3
- CVE-2024-0155Dell Digital Delivery, versions prior to 5.2.0.0, contain a …7.8
Are you affected by CVE-2024-0148?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
