CVE-2026-24148

8.3

NVIDIA · Jetson

NVIDIA Jetson for JetPack contains an initialization vulnerability in the system logic that allows an authenticated attacker to trigger insecure resource defaults.

Executive summary

An insecure default configuration vulnerability in NVIDIA Jetson systems could allow an attacker to access encrypted data, tamper with information, or cause a partial denial of service.

Vulnerability

This flaw involves improper initialization of resources with insecure defaults, which can be exploited by an authenticated, low-privileged attacker to compromise system integrity.

Business impact

Successful exploitation poses a significant risk to data confidentiality and integrity, potentially allowing unauthorized parties to access encrypted sensitive information or manipulate critical data. Given the CVSS score of 8.3, this vulnerability is classified as High severity. The impact on system availability and the potential for cross-device compromise in multi-tenant or shared environments present a substantial threat to operational security.

Remediation

Immediate Action: Update NVIDIA Jetson Xavier and Orin series devices to version 35.6.4 or 36.5, respectively, to implement the necessary security patches.

Proactive Monitoring: Monitor system logs for unauthorized configuration changes or unexpected device behavior, particularly during the initialization or boot sequences.

Compensating Controls: Restrict local access to hardware interfaces and ensure that devices are placed within protected network segments to limit the reach of potential attackers.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The high severity of this vulnerability necessitates immediate attention to prevent potential data compromise and system instability. IT administrators should prioritize the deployment of the provided firmware updates across all affected Jetson hardware to ensure the initialization logic is correctly secured.

More NVIDIA CVEs

Sources