NVIDIA NVDebug tool: NVDebug can be induced to write files into restricted components, reaching data tampering
CVSS 7.6CVE-2025-23343NVIDIA / GPU stackcurated
Impact
NVDebug can be induced to write files into restricted components, reaching data tampering and information disclosure with a changed scope on a DGX/HGX platform host.
Who can reach it
Adjacent network, low privileges, user interaction, high complexity. Narrow, but the target is a platform-management host.
What to do
Update NVDebug per bulletin 5696. Cost: trivial - replace the tool bundle. No node drain.
References
Related entries
- NVIDIA NVDebug tool: NVDebug allows an actor to run code on the platform host as a non-privileged user, reaching codeCVE-2025-23344 · NVIDIA NVDebug toolHigh
- NVIDIA NVDebug tool: The NVDebug diagnostic collector lets an actor gain access to a privileged account, reaching codeCVE-2025-23342 · NVIDIA NVDebug toolHigh
- NVIDIA Jetson Linux (UEFI): UEFI accepts a Linux Device Tree without checking authorization, so anyone who reachesCVE-2025-33182 · NVIDIA Jetson Linux (UEFI)High
- NVIDIA NeMo Agent Toolkit (Web UI): The chat API endpoint is vulnerable to server-side request forgery, so an attackerCVE-2025-33203 · NVIDIA NeMo Agent Toolkit (Web UI)High
- NVIDIA Jetson Linux (initrd command-line handling): An attacker with physical access and no credentials at all canCVE-2026-24154 · NVIDIA Jetson Linux (initrd command-line handling)High
- NVIDIA GPU firmware microcontroller (Falcon): A privileged user can craft microcode that the GPU's internalCVE-2021-23201 · NVIDIA GPU firmware microcontroller (Falcon)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.