CVE-2025-23261
BaseFortify
Publication date: 2025-09-04
Last updated on: 2025-09-05
Assigner: NVIDIA Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nvidia | cumulus_linux | * |
| nvidia | nvos | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-532 | The product writes sensitive information to a log file. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability affects NVIDIA Cumulus Linux and NVOS products where hashed user passwords are not properly suppressed in log files. This means that sensitive information, specifically hashed passwords, can be recorded in logs where unauthorized users might access them, potentially leading to information disclosure. [1]
How can this vulnerability impact me? :
The vulnerability can lead to the disclosure of hashed user passwords to unauthorized users if they gain access to the log files. This can compromise the confidentiality of user credentials, potentially allowing attackers to misuse or attempt to crack these passwords. The impact is limited to confidentiality with no effect on integrity or availability. [1]