7.1
/ 10
HIGH
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Description
NVIDIA Jetson Linux contains a vulnerability in UEFI Management mode, where an unprivileged local attacker may cause exposure of sensitive information via a side channel vulnerability. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
Basic Information
ID
CVE-2025-23270
Source
nvidia
Published
Jul 17, 2025 at 19:59
Modified
Jul 17, 2025 at 20:21
Affected Product
Vendor
NVIDIA
Product
Jetson Orin, IGX Orin and Xavier Devices
Version
NVIDIA Jetson Orin Series All versions prior to JP5.x: 35.6.2
Affected Versions
NVIDIA Jetson Orin, IGX Orin and Xavier Devices NVIDIA Jetson Orin Series All versions prior to JP5.x: 35.6.2
NVIDIA Jetson Orin, IGX Orin and Xavier Devices NVIDIA Jetson Orin Series All versions prior to JP6.x: 36.4.4
NVIDIA Jetson Orin, IGX Orin and Xavier Devices NVIDIA Xavier Series All versions prior to JP5.x: 35.6.2
NVIDIA Jetson Orin, IGX Orin and Xavier Devices IGX Orin All versions prior to IGX 1.1.2
NVIDIA Jetson Orin, IGX Orin and Xavier Devices NVIDIA Jetson Orin Series All versions prior to JP6.x: 36.4.4
NVIDIA Jetson Orin, IGX Orin and Xavier Devices NVIDIA Xavier Series All versions prior to JP5.x: 35.6.2
NVIDIA Jetson Orin, IGX Orin and Xavier Devices IGX Orin All versions prior to IGX 1.1.2