Vulnerability record · CVE-2023-25518 · published 23 June 2023
CVE-2023-25518: Nvidia jetson linux vulnerability
Nvidia · Jetson Linux
NVIDIA Jetson contains a vulnerability in CBoot, where the PCIe controller is initialized without IOMMU, which may allow an attacker with physical access to the target device to read and write to arbitrary memory. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and loss of integrity.
Description
NVIDIA Jetson contains a vulnerability in CBoot, where the PCIe controller is initialized without IOMMU, which may allow an attacker with physical access to the target device to read and write to arbitrary memory. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and loss of integrity.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://https://nvidia.custhelp.com/app/answers/detail/a_id/5466 | Vendor Advisory |
| https://https://nvidia.custhelp.com/app/answers/detail/a_id/5466 | Vendor Advisory |
Track CVE-2023-25518 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-25518), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.