CVE-2025-23262 Details
Description
NVIDIA ConnectX contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modify the configuration. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.
A vulnerability exists in the management interface of NVIDIA ConnectX products, specifically in versions prior to 45.1020, 35.4554, 39.5050, and 43.3608, as well as in ConnectX-4 and ConnectX-4 LX versions prior to 12.28.4704 and 14.32.1908, respectively. This vulnerability allows an attacker with local access to manipulate authorization processes, potentially leading to unauthorized configuration changes. Exploitation of this issue could result in a denial-of-service, unauthorized privilege escalation, information disclosure, and data tampering.
Users are advised to update to version 45.1020 for ConnectX GA products, version 35.4554 for ConnectX LTS22, version 39.5050 for ConnectX LTS23, and version 43.3608 for ConnectX LTS24. For ConnectX-4 and ConnectX-4 LX, versions 12.28.4704 and 14.32.1908 will be published by the end of September.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2025CISA-ADP
Assessed Sep 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://nvd.nist.gov/vuln/detail/CVE-2025-23262 | [email protected] | Advisory |
| https://nvidia.custhelp.com/app/answers/detail/a_id/5655 | [email protected] | AdvisoryBundleRemedyVendor |
| https://www.cve.org/CVERecord?id=CVE-2025-23262 | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| NVIDIA ConnectX | < 45.1020 < 35.4554 < 39.5050 < 43.3608 < 12.28.4704 (semver) < 14.32.1908 (semver) |
CPE
Remediation
| |
| NVIDIA ConnectX-6 DE | All versions |
CPE
Remediation
| |
| NVIDIA ConnectX-6 DX | All versions |
CPE
Remediation
| |
| NVIDIA ConnectX-6 LX | All versions |
CPE
Remediation
| |
| NVIDIA ConnectX-7 | All versions |
CPE
Remediation
| |
| NVIDIA ConnectX-8 | All versions |
CPE
Remediation
| |
| NVIDIA ConnectX-5 | All versions |
CPE
Remediation
| |
| NVIDIA ConnectX-4 | All versions |
CPE
Remediation
| |
| NVIDIA ConnectX-4 LX | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2025 | New CVE Received | [email protected] |
Volerion