CVE-2025-23270
NVIDIA Jetson Linux contains a vulnerability in UEFI Management mode, where an unprivileged local attacker may cause exposure of sensitive information via a side channel vulnerability. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Puntuación base: 7.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.19%
- Percentil entre todas las CVEs puntuadas: 8
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1091Replication Through Removable Medialateral movement · initial access75 % - Impacto principal
T1005Data from Local Systemcollection80 % - Impacto secundario
T1059Command and Scripting Interpreterexecution70 % - Impacto secundario
T1565Data Manipulationimpact65 %
AV:P indica acceso físico a Jetson Linux; T1091 (medios extraíbles/hardware). Side channel exposure + code execution potential: T1005 (lectura datos), T1059 (ejecución código), T1565 (manipulación datos).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-392
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-23270",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-23270",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-07-17T20:21:29.502391Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@nvidia.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "PHYSICAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 0.5
}
]
},
"affected": [
{
"source": "psirt@nvidia.com",
"affectedData": [
{
"vendor": "NVIDIA",
"product": "Jetson Orin, IGX Orin and Xavier Devices",
"versions": [
{
"status": "affected",
"version": "NVIDIA Jetson Orin Series All versions prior to JP5.x: 35.6.2"
},
{
"status": "affected",
"version": "NVIDIA Jetson Orin Series All versions prior to JP6.x: 36.4.4"
},
{
"status": "affected",
"version": "NVIDIA Xavier Series All versions prior to JP5.x: 35.6.2"
},
{
"status": "affected",
"version": "IGX Orin All versions prior to IGX 1.1.2"
}
],
"platforms": [
"Jetson Linux",
"IGX OS"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-07-17T20:15:28.993",
"references": [
{
"url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5662",
"source": "psirt@nvidia.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@nvidia.com",
"description": [
{
"lang": "en",
"value": "CWE-392"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "NVIDIA Jetson Linux contains a vulnerability in UEFI Management mode, where an unprivileged local attacker may cause exposure of sensitive information via a side channel vulnerability. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure."
},
{
"lang": "es",
"value": "NVIDIA Jetson Linux contiene una vulnerabilidad en el modo de administración UEFI, donde un atacante local sin privilegios puede exponer información confidencial mediante una vulnerabilidad de canal lateral. Una explotación exitosa de esta vulnerabilidad podría provocar ejecución de código, manipulación de datos, denegación de servicio y divulgación de información."
}
],
"lastModified": "2026-06-17T08:53:04.947",
"sourceIdentifier": "psirt@nvidia.com"
}