CVE-2025-23262: NVIDIA Connectx-4
Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.
NVIDIA ConnectX contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modify the configuration. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.
Affected products
- NVIDIA Connectx-4: before 12.28.2704 (fixed in 12.28.2704)
- NVIDIA Connectx-4 Lx: before 14.32.1908 (fixed in 14.32.1908)
- NVIDIA Connectx Ga: before 45.1020 (fixed in 45.1020)
- NVIDIA Connectx LTS22: before 35.4554 (fixed in 35.4554)
- NVIDIA Connectx LTS23: before 39.5050 (fixed in 39.5050)
- NVIDIA Connectx LTS24: before 43.3608 (fixed in 43.3608)
Published 2025-09-04. Last modified 2026-06-17.