Metrics
Affected Vendors & Products
| Link | Providers | 
|---|---|
| https://nvidia.custhelp.com/app/answers/detail/a_id/5630 | 
                     | 
            
Thu, 01 May 2025 15:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-502 | |
| References | 
         | 
Thu, 01 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Thu, 01 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-502 | |
| References | 
         | 
Thu, 01 May 2025 14:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | NVIDIA TensorRT-LLM for any platform contains a vulnerability in python executor where an attacker may cause a data validation issue by local access to the TRTLLM server. A successful exploit of this vulnerability may lead to code execution, information disclosure and data tampering. | NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows a guest to access global resources. A successful exploit of this vulnerability might lead to denial of service. | 
| Weaknesses | CWE-502 | CWE-732 | 
| References | ||
| Metrics | 
        
        
        cvssV3_1
         
  | 
    
        
        
        cvssV3_1
         
  | 
Thu, 01 May 2025 14:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | NVIDIA TensorRT-LLM for any platform contains a vulnerability in python executor where an attacker may cause a data validation issue by local access to the TRTLLM server. A successful exploit of this vulnerability may lead to code execution, information disclosure and data tampering. | |
| Weaknesses | CWE-502 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: nvidia
Published: 2025-05-01T13:53:48.765Z
Updated: 2025-05-01T14:52:22.664Z
Reserved: 2025-01-14T01:06:19.964Z
Link: CVE-2025-23245
Updated: 2025-05-01T14:52:18.602Z
Status : Awaiting Analysis
Published: 2025-05-01T14:15:36.250
Modified: 2025-05-02T13:53:20.943
Link: CVE-2025-23245
No data.