CVE-2025-23261Log File Information Exposure in Nvidia Cumulus Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 95.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 4
Latest updateSep 5

Description

NVIDIA Cumulus Linux and NVOS products contain a vulnerability, where hashed user passwords are not properly suppressed in log files, potentially disclosing information to unauthorized users.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5nvidia/cumulus_linuxCumulus Linux 5.12, 5.11, 5.10, 5.9 and older
CVEListV5nvidia/nvosNVOS 25.02.21xx, 25.02.22xx, 25.02.23xx, NVOS 25.02.3xxx+1

🔴Vulnerability Details

2
GHSA
GHSA-j2cv-h84f-x9r9: NVIDIA Cumulus Linux and NVOS products contain a vulnerability, where hashed user passwords are not properly suppressed in log files, potentially disc2025-09-05
CVEList
CVE-2025-23261: NVIDIA Cumulus Linux and NVOS products contain a vulnerability, where hashed user passwords are not properly suppressed in log files, potentially disc2025-09-04
CVE-2025-23261 — Log File Information Exposure | cvebase