cbcvebase.

Nvidia Connectx Lts23 vulnerabilities

5 known vulnerabilities affecting nvidia/connectx_lts23.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2025-23350P3CRITICALCVSS 9.0vAll versions prior to 39.80022026-07-01
CVE-2025-23350 [CRITICAL] CWE-787 CVE-2025-23350: NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user wi NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device.
nvd
CVE-2025-23351P3CRITICALCVSS 9.0vAll versions prior to 39.80022026-07-01
CVE-2025-23351 [CRITICAL] CWE-787 CVE-2025-23351: NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user wi NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device.
nvd
CVE-2024-0105P3HIGHCVSS 8.9vAll versions prior to xx.39.35602024-11-01
CVE-2024-0105 [HIGH] CWE-274 CVE-2024-0105: NVIDIA ConnectX Firmware contains a vulnerability where an attacker may cause an improper handling o NVIDIA ConnectX Firmware contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue. A successful exploit of this vulnerability may lead to denial of service, data tampering, and limited information disclosure.
nvd
CVE-2025-23299P4MEDIUMCVSS 6.7vAll versions prior to 39.50502025-10-22
CVE-2025-23299 [MEDIUM] CWE-787 CVE-2025-23299: NVIDIA Bluefield and ConnectX contain a vulnerability in the management interface that could allow a NVIDIA Bluefield and ConnectX contain a vulnerability in the management interface that could allow a malicious actor with high privilege access to execute arbitrary code.
nvd
CVE-2025-23262P4MEDIUMCVSS 6.3vAll versions prior to 39.50502025-09-04
CVE-2025-23262 [MEDIUM] CWE-863 CVE-2025-23262: NVIDIA ConnectX contains a vulnerability in the management interface, where an attacker with local a NVIDIA ConnectX contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modify the configuration. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.
nvd