CVE-2025-23262Incorrect Authorization in Nvidia Connectx-4

Severity
6.3MEDIUMNVD
EPSS
0.0%
top 93.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 4
Latest updateSep 5

Description

NVIDIA ConnectX contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modify the configuration. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:HExploitability: 0.8 | Impact: 5.5

Affected Packages6 packages

CVEListV5nvidia/connectx-4All versions prior to 12.28.2704
CVEListV5nvidia/connectx_gaAll versions prior to 45.1020
CVEListV5nvidia/connectx-4_lxAll versions prior to 14.32.1908
CVEListV5nvidia/connectx_lts22All versions prior to 35.4554
CVEListV5nvidia/connectx_lts23All versions prior to 39.5050

🔴Vulnerability Details

2
GHSA
GHSA-cq7v-6gr4-8hx4: NVIDIA ConnectX contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modif2025-09-05
CVEList
CVE-2025-23262: NVIDIA ConnectX contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modif2025-09-04
CVE-2025-23262 — Incorrect Authorization in Nvidia | cvebase