CVE-2025-23270: CWE-392: Missing Report of Error Condition in NVIDIA Jetson Orin, IGX Orin and Xavier Devices
NVIDIA Jetson Linux contains a vulnerability in UEFI Management mode, where an unprivileged local attacker may cause exposure of sensitive information via a side channel vulnerability. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
CVE-2025-23270: CWE-392: Missing Report of Error Condition in NVIDIA Jetson Orin, IGX Orin and Xavier Devices
Description
NVIDIA Jetson Linux contains a vulnerability in UEFI Management mode, where an unprivileged local attacker may cause exposure of sensitive information via a side channel vulnerability. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- nvidia
- Date Reserved
- 2025-01-14T01:06:23.292Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 68795a0ca83201eaace8b89d
Added to database: 7/17/2025, 8:16:12 PM
Last updated: 7/17/2025, 8:16:12 PM
Views: 1
Related Threats
CVE-2025-7754: SQL Injection in code-projects Patient Record Management System
MediumCVE-2025-7753: SQL Injection in code-projects Online Appointment Booking System
MediumCVE-2025-46102: n/a
MediumCVE-2025-34125: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in D-Link DSP-W110A1
CriticalCVE-2025-7752: SQL Injection in code-projects Online Appointment Booking System
MediumActions
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.