CVE-2025-23256: NVIDIA Bluefield Ga

High severity, CVSS 8.7. EPSS: 0.1% chance of exploitation in the next 30 days.

NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modify the configuration. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.

Affected products

  • NVIDIA Bluefield Ga: before 45.1020 (fixed in 45.1020)
  • NVIDIA Bluefield LTS22: before 35.4554 (fixed in 35.4554)
  • NVIDIA Bluefield LTS23: before 39.5050 (fixed in 39.5050)
  • NVIDIA Bluefield LTS24: before 43.3608 (fixed in 43.3608)

Published 2025-09-04. Last modified 2026-06-17.