CVE-2025-23256
BaseFortify
Publication date: 2025-09-04
Last updated on: 2025-09-05
Assigner: NVIDIA Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nvidia | bluefield | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-863 | The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
CVE-2025-23256 is a vulnerability in the NVIDIA BlueField management interface where an attacker with local access can bypass proper authorization controls to modify device configuration. This incorrect authorization flaw allows unauthorized changes to the system settings. [1]
How can this vulnerability impact me? :
Exploiting this vulnerability can lead to denial of service, escalation of privileges, information disclosure, and data tampering. This means an attacker could disrupt service availability, gain higher access rights, access sensitive information, or alter data integrity. [1]