CVE-2025-23262: NVIDIA Connectx-4

Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.

NVIDIA ConnectX contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modify the configuration. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.

Affected products

  • NVIDIA Connectx-4: before 12.28.2704 (fixed in 12.28.2704)
  • NVIDIA Connectx-4 Lx: before 14.32.1908 (fixed in 14.32.1908)
  • NVIDIA Connectx Ga: before 45.1020 (fixed in 45.1020)
  • NVIDIA Connectx LTS22: before 35.4554 (fixed in 35.4554)
  • NVIDIA Connectx LTS23: before 39.5050 (fixed in 39.5050)
  • NVIDIA Connectx LTS24: before 43.3608 (fixed in 43.3608)

Published 2025-09-04. Last modified 2026-06-17.