CVE-2025-23293 Details
Description
NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized action. A successful exploit of this vulnerability may lead to information disclosure.
A vulnerability in the Delegated Licensing Service (DLS) component of the NVIDIA License System for all appliance platforms allows an authenticated user to perform authorized actions that could lead to unauthorized information disclosure. This vulnerability is present in all versions prior to 3.5.1 and 3.1.7.
Users are advised to update to DLS version 3.5.1 or 3.1.7. For guidance on upgrading an existing DLS virtual appliance, refer to the 'Migrating a DLS Instance' section in the NVIDIA License System User Guide.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2025CISA-ADP
Assessed Sep 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://nvd.nist.gov/vuln/detail/CVE-2025-23293 | [email protected] | AdvisoryNot Applicable |
| https://nvidia.custhelp.com/app/answers/detail/a_id/5705 | [email protected] | AdvisoryBundleRemedyVendor |
| https://www.cve.org/CVERecord?id=CVE-2025-23293 | [email protected] | Not Applicable |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| NVIDIA Delegated Licensing Service | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2025 | New CVE Received | [email protected] |
Volerion