CVE-2023-25517: High severity nvidia gpu driver vulnerability
Published Jul 3, 2023
·Updated
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest OS may be able to control resources for which it is not authorized, which may lead to information disclosure and data tampering.
Affected Software
6 affected components
Nvidia GPU Display Driver<11.13
Nvidia GPU Display Driver>=13.0<13.8
Nvidia GPU Display Driver>=15.0<15.3
Citrix Hypervisor
redhat Enterprise Linux Kernel-based Virtual Machine
VMware vSphere
Event History
Jul 3, 2023
CVE Published
via MITRE·11:27 PM
Data Sourced
via MITRE·11:27 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this NVIDIA vGPU vulnerability?
The vulnerability ID for this NVIDIA vGPU vulnerability is CVE-2023-25517.
2
What is the severity of CVE-2023-25517?
CVE-2023-25517 has a severity value of 7.1 (high).
3
What is the affected software for CVE-2023-25517?
The affected software for CVE-2023-25517 includes NVIDIA GPU Display Driver versions 11.13, 13.0 to 13.8, and 15.0 to 15.3.
4
What is the impact of CVE-2023-25517?
CVE-2023-25517 may lead to information disclosure and data tampering.
5
Where can I find more information about CVE-2023-25517?
You can find more information about CVE-2023-25517 at this reference link: [https://nvidia.custhelp.com/app/answers/detail/a_id/5468](https://nvidia.custhelp.com/app/answers/detail/a_id/5468).