# CVE-2025-23263

## Summary

- **CVE ID:** CVE-2025-23263
- **Severity:** HIGH
- **CVSS Score:** 7.6 (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H)
- **CWE:** CWE-279
- **Published:** Jul 17, 2025
- **Last Modified:** Mar 13, 2026

## Description

NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause escalation of privileges and denial of service on the VLAN.

## Affected Products

- NVIDIA — DOCA-Host and Mellanox OFED (DOCA-Host All versions prior to 2.5.4-0.0.9)
- NVIDIA — DOCA-Host and Mellanox OFED (DOCA-Host All versions prior to 2.9.3-0.2.2)
- NVIDIA — DOCA-Host and Mellanox OFED (DOCA-Host All versions prior to 3.0.0-058001)
- NVIDIA — DOCA-Host and Mellanox OFED (Mellanox OFED All versions prior to 5.8-7.0.6.1)
- NVIDIA — DOCA-Host and Mellanox OFED (Mellanox OFED All versions prior to 23.10-5.1.4.0)
- NVIDIA — DOCA-Host and Mellanox OFED (Mellanox OFED All versions prior to 24.10-3.2.5.0)

## References

- [CNA](https://nvidia.custhelp.com/app/answers/detail/a_id/5654)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.18%
- **EPSS Percentile:** 7.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._