NVIDIA License System - Delegated Licensing Service (DLS): SQL injection in the DLS appliance reaching a high integrity
CVSS 4.6CVE-2025-23292NVIDIA / GPU stackcurated
Impact
SQL injection in the DLS appliance reaching a high integrity impact and partial denial of service in the UI - an authenticated attacker can alter licensing records.
Who can reach it
Adjacent network, high privileges, user interaction. An admin-level account on the licensing appliance.
What to do
Update the DLS appliance per bulletin 5705 and review licensing records for tampering. Cost: appliance restart.
References
Related entries
- NVIDIA License System - Delegated Licensing Service (DLS): Improper authentication in the DLS lets an unauthenticatedCVE-2026-24241 · NVIDIA License System - Delegated Licensing Service (DLS)Medium
- NVIDIA License System - Delegated Licensing Service (DLS): An authorised-looking action leads to information disclosureCVE-2025-23291 · NVIDIA License System - Delegated Licensing Service (DLS)Low
- NVIDIA License System - Delegated Licensing Service (DLS): An unauthorised action against the DLS reaches highCVE-2025-23293 · NVIDIA License System - Delegated Licensing Service (DLS)High
- NVIDIA License System - Delegated Licensing Service (DLS): An unauthorised action against the DLS reaches partialCVE-2024-0122 · NVIDIA License System - Delegated Licensing Service (DLS)High
- NVDebug tool: Info disclosure / privesc via diagnostic toolCVE-2025-23252 · NVDebug toolMedium
- CUDA Toolkit: Info disclosure (buffer over-read)CVE-2025-23274 · CUDA ToolkitMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.