
CVE-2024-0148
https://notcve.org/view.php?id=CVE-2024-0148
25 Feb 2025 — NVIDIA Jetson Linux and IGX OS image contains a vulnerability in the UEFI firmware RCM boot mode, where an unprivileged attacker with physical access to the device could load untrusted code. A successful exploit might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. The scope of the impacts can extend to other components. • https://nvidia.custhelp.com/app/answers/detail/a_id/5617 • CWE-447: Unimplemented or Unsupported Feature in UI •

CVE-2024-0112
https://notcve.org/view.php?id=CVE-2024-0112
11 Feb 2025 — NVIDIA Jetson AGX Orin™ and NVIDIA IGX Orin software contain a vulnerability where an attacker can cause an improper input validation issue by escalating certain permissions to a limited degree. A successful exploit of this vulnerability might lead to code execution, denial of service, data corruption, information disclosure, or escalation of privilege. • https://nvidia.custhelp.com/app/answers/detail/a_id/5611 • CWE-20: Improper Input Validation •