2.4
CVE-2025-23291
- EPSS 0.01%
- Veröffentlicht 30.09.2025 18:15:49
- Zuletzt bearbeitet 02.10.2025 19:12:17
- Quelle psirt@nvidia.com
- CVE-Watchlists
- Unerledigt
NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized action. A successful exploit of this vulnerability may lead to information disclosure.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerNVIDIA
≫
Produkt
DLS component of NVIDIA License System
Default Statusunaffected
Version
All versions prior to v3.5.1 and v3.1.7
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.01% | 0.003 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@nvidia.com | 2.4 | 0.7 | 1.4 |
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N
|
CWE-312 Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.