NVIDIA License System - Delegated Licensing Service (DLS): An authorised-looking action leads to information disclosure
CVSS 2.4CVE-2025-23291NVIDIA / GPU stackcurated
Impact
An authorised-looking action leads to information disclosure from the licensing service. Low severity and high complexity, but it is inventory data about your entire vGPU estate.
Who can reach it
Adjacent network, high privileges and user interaction required - realistically an insider or a compromised admin session.
What to do
Update the DLS appliance per bulletin 5705. Cost: appliance restart, no tenant impact.
References
Related entries
- NVIDIA License System - Delegated Licensing Service (DLS): An unauthorised action against the DLS reaches highCVE-2025-23293 · NVIDIA License System - Delegated Licensing Service (DLS)High
- NVIDIA License System - Delegated Licensing Service (DLS): An unauthorised action against the DLS reaches partialCVE-2024-0122 · NVIDIA License System - Delegated Licensing Service (DLS)High
- NVIDIA License System - Delegated Licensing Service (DLS): SQL injection in the DLS appliance reaching a high integrityCVE-2025-23292 · NVIDIA License System - Delegated Licensing Service (DLS)Medium
- NVIDIA License System - Delegated Licensing Service (DLS): Improper authentication in the DLS lets an unauthenticatedCVE-2026-24241 · NVIDIA License System - Delegated Licensing Service (DLS)Medium
- NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmware: A third resource-reuse path in SROOT firmware leaksCVE-2025-33200 · NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmwareLow
- GPU Display Driver: Physical memory accessCVE-2023-0194 · GPU Display DriverLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.