NVIDIA Riva: Unauthorized access to the speech service (insufficient access control)
CVSS 7.3CVE-2025-23242NVIDIA / GPU stackcurated
Impact
Unauthorized access to the speech service (insufficient access control)
Who can reach it
Network client of the Riva endpoint
What to do
Upgrade Riva NIM containers; redeploy; put auth in front of the endpoint
Fleet impact
How widespread
Common - shipped as a NIM-style microservice, deployed by neoclouds offering managed speech endpoints
Cost to remediate
daemon-restart (upgrade to Riva 2.19.0 and redeploy the service)
Why it hits the whole fleet
Improper access control in the service auth layer, network-reachable with no user interaction: an unauthenticated caller escalates privileges into the hosting cloud environment and can read other tenants' data
References
Related entries
- NVIDIA Riva: Weak authenticationCVE-2025-23243 · NVIDIA RivaMedium
- NVIDIA DOCA: Local privesc via insecure file permissionsCVE-2025-23257 · NVIDIA DOCAHigh
- NVIDIA DOCA: Local privesc via insecure file permissionsCVE-2025-23258 · NVIDIA DOCAHigh
- GPU Display Driver: Access-control bypassCVE-2025-23277 · GPU Display DriverHigh
- NVIDIA NVDebug tool: NVDebug allows an actor to run code on the platform host as a non-privileged user, reaching codeCVE-2025-23344 · NVIDIA NVDebug toolHigh
- Cumulus Linux / NVOS: Command injection (local)CVE-2025-33181 · Cumulus Linux / NVOSHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.