NVIDIA License System - Delegated Licensing Service (DLS): Improper authentication in the DLS lets an unauthenticated
CVSS 4.3CVE-2026-24241NVIDIA / GPU stackcurated
Impact
Improper authentication in the DLS lets an unauthenticated attacker on an adjacent network read information from the licensing service.
Who can reach it
Adjacent network, no privileges, no user interaction - the weakest precondition of the DLS set.
What to do
Update the DLS appliance per bulletin 5789. Cost: appliance restart, no tenant impact.
References
Related entries
- NVIDIA License System - Delegated Licensing Service (DLS): An authorised-looking action leads to information disclosureCVE-2025-23291 · NVIDIA License System - Delegated Licensing Service (DLS)Low
- NVIDIA License System - Delegated Licensing Service (DLS): An unauthorised action against the DLS reaches highCVE-2025-23293 · NVIDIA License System - Delegated Licensing Service (DLS)High
- NVIDIA License System - Delegated Licensing Service (DLS): An unauthorised action against the DLS reaches partialCVE-2024-0122 · NVIDIA License System - Delegated Licensing Service (DLS)High
- NVIDIA License System - Delegated Licensing Service (DLS): SQL injection in the DLS appliance reaching a high integrityCVE-2025-23292 · NVIDIA License System - Delegated Licensing Service (DLS)Medium
- GeForce NOW Android app: Info disclosure / code exec via implicit intentCVE-2023-31014 · GeForce NOW Android appMedium
- DGX A100 SBIOS: Buffer overflow in SBIOSCVE-2023-31031 · DGX A100 SBIOSMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.