CVE-2025-23263
NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause escalation of privileges and denial of service on the VLAN.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.6
- CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
- EPSS probability
- 0.18%
- CWE
- CWE-279
- Published
- 2025-07-17
- Last modified
- 2026-03-13
Affected products
- NVIDIA DOCA-Host and Mellanox OFED
- NVIDIA DOCA-Host and Mellanox OFED
- NVIDIA DOCA-Host and Mellanox OFED
- NVIDIA DOCA-Host and Mellanox OFED
- NVIDIA DOCA-Host and Mellanox OFED
- NVIDIA DOCA-Host and Mellanox OFED
Weakness type
Related vulnerabilities
- CVE-2026-46388 — osquery: Unprivileged users can temporarily read file carve contents
- CVE-2026-4948 — Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization
- CVE-2026-20062 — A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in...
- CVE-2025-12801 — Nfs-utils: rpc.mountd in the nfs-utils privilege escalation
- CVE-2025-14025 — Ansible-automation-platform/aap-gateway: aap-gateway: read-only personal access token (pat) bypasses write restrictions
- CVE-2025-36228 — Incorrect Execution-Assigned Permissions in IBM Aspera Faspex
- CVE-2025-13663 — Quartus Prime Pro Edition Installer Advisory
- CVE-2024-25621 — containerd affected by a local privilege escalation via wide permissions on CRI directory