CVE-2025-23299

Severity
6.7MEDIUM
EPSS
0.0%
top 95.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 22

Description

NVIDIA Bluefield and ConnectX contain a vulnerability in the management interface that could allow a malicious actor with high privilege access to execute arbitrary code.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages9 packages

CVEListV5nvidia/connectx_gaAll versions prior to 46.1006
CVEListV5nvidia/bluefield_gaAll versions prior to 46.1006
CVEListV5nvidia/connectx-4_lxAll versions prior to 32.1908
CVEListV5nvidia/connectx_lts22All versions prior to 35.4554
CVEListV5nvidia/connectx_lts23All versions prior to 39.5050

🔴Vulnerability Details

2
GHSA
GHSA-rm5x-vf5q-5mp5: NVIDIA Bluefield and ConnectX contain a vulnerability in the management interface that could allow a malicious actor with high privilege access to exe2025-10-22
CVEList
CVE-2025-23299: NVIDIA Bluefield and ConnectX contain a vulnerability in the management interface that could allow a malicious actor with high privilege access to exe2025-10-22
CVE-2025-23299 (MEDIUM CVSS 6.7) | NVIDIA Bluefield and ConnectX conta | cvebase.io