CVE-2023-25520: Input Validation
Published Jun 23, 2023
·Updated
NVIDIA Jetson Linux Driver Package contains a vulnerability in nvbootctrl, where a privileged local attacker can configure invalid settings, resulting in denial of service.
Affected Software
5 affected components
Nvidia Jetson Linux<32.7.4
Nvidia Jetson AGX Xavier
Nvidia Jetson TX2
Nvidia Jetson Tx2 Nx
Nvidia Jetson Xavier NX
Event History
Jun 23, 2023
CVE Published
via MITRE·05:23 PM
Data Sourced
via MITRE·05:23 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-25520.
2
What is the title of this vulnerability?
The title of this vulnerability is 'NVIDIA Jetson Linux Driver Package contains a vulnerability in nvbootctrl where a privileged local attacker can configure invalid settings, resulting in denial of service.'
3
What is the severity of CVE-2023-25520?
The severity of CVE-2023-25520 is medium with a severity value of 5.5.
4
Which software is affected by CVE-2023-25520?
The NVIDIA Jetson Linux Driver Package with a version up to 32.7.4 is affected by CVE-2023-25520.
5
How can a privileged local attacker exploit this vulnerability?
A privileged local attacker can exploit this vulnerability by configuring invalid settings in nvbootctrl, leading to denial of service.