CVE-2025-23256

Severity
8.7HIGH
EPSS
0.0%
top 95.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 4
Latest updateSep 5

Description

NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modify the configuration. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:HExploitability: 2.0 | Impact: 6.0

Affected Packages4 packages

CVEListV5nvidia/bluefield_gaAll versions prior to 45.1020
CVEListV5nvidia/bluefield_lts22All versions prior to 35.4554
CVEListV5nvidia/bluefield_lts23All versions prior to 39.5050
CVEListV5nvidia/bluefield_lts24All versions prior to 43.3608

🔴Vulnerability Details

2
GHSA
GHSA-cf8m-72r3-jm23: NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modi2025-09-05
CVEList
CVE-2025-23256: NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modi2025-09-04
CVE-2025-23256 (HIGH CVSS 8.7) | NVIDIA BlueField contains a vulnera | cvebase.io