Skip to main content

CVE-2025-23270: CWE-392: Missing Report of Error Condition in NVIDIA Jetson Orin, IGX Orin and Xavier Devices

High
VulnerabilityCVE-2025-23270cvecve-2025-23270cwe-392
Published: Thu Jul 17 2025 (07/17/2025, 19:59:24 UTC)
Source: CVE Database V5
Vendor/Project: NVIDIA
Product: Jetson Orin, IGX Orin and Xavier Devices

Description

NVIDIA Jetson Linux contains a vulnerability in UEFI Management mode, where an unprivileged local attacker may cause exposure of sensitive information via a side channel vulnerability. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.

Technical Details

Data Version
5.1
Assigner Short Name
nvidia
Date Reserved
2025-01-14T01:06:23.292Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 68795a0ca83201eaace8b89d

Added to database: 7/17/2025, 8:16:12 PM

Last updated: 7/17/2025, 8:16:12 PM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats