CVE-2018-6242

MEDIUM

Nvidia Tegra Bootrom Rcm - Memory Corruption

Title source: rule
STIX 2.1

Description

Some NVIDIA Tegra mobile processors released prior to 2016 contain a buffer overflow vulnerability in BootROM Recovery Mode (RCM). An attacker with physical access to the device's USB and the ability to force the device to reboot into RCM could exploit the vulnerability to execute unverified code.

Exploits (6)

nomisec WORKING POC 552 stars
by DavidBuchanan314 · poc
https://github.com/DavidBuchanan314/NXLoader
nomisec WORKING POC 21 stars
by reswitched · poc
https://github.com/reswitched/rcm-modchips
nomisec WORKING POC 4 stars
by austinhartzheim · poc
https://github.com/austinhartzheim/fusee-gelee
nomisec WORKING POC 1 stars
by Resi-le · poc
https://github.com/Resi-le/NXLoader
nomisec NO CODE 1 stars
by nikameru · poc
https://github.com/nikameru/nxboot
nomisec WORKING POC
by Swiftloke · poc
https://github.com/Swiftloke/fusee-toy

Scores

CVSS v3 6.8
EPSS 0.1182
EPSS Percentile 93.7%
Attack Vector PHYSICAL
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (1)
nvidia/tegra_bootrom_rcm
Published May 01, 2018
Tracked Since Feb 18, 2026