2.4
CVE-2025-23291
- EPSS 0.01%
- Veröffentlicht 30.09.2025 18:15:49
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle psirt@nvidia.com
- CVE-Watchlists
- Unerledigt
NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized action. A successful exploit of this vulnerability may lead to information disclosure.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerNVIDIA
≫
Produkt
DLS component of NVIDIA License System
Default Statusunaffected
Version
All versions prior to v3.5.1 and v3.1.7
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.01% | 0.005 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@nvidia.com | 2.4 | 0.7 | 1.4 |
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N
|
CWE-312 Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.