CVE-2025-23293
8.7NVIDIA · Delegated Licensing Service
NVIDIA Delegated Licensing Service contains a missing authentication vulnerability that allows a local user or attacker to perform unauthorized actions, potentially leading to information disclosure.
Executive summary
A critical vulnerability in the NVIDIA Delegated Licensing Service allows an authenticated user to perform unauthorized actions, creating a significant risk of information disclosure and service disruption.
Vulnerability
The software suffers from a missing authentication for critical function (CWE-306) flaw, which allows an attacker with low-level privileges (PR:L) to interact with the licensing service without proper authorization.
Business impact
The ability for an unauthorized user to perform administrative or critical licensing actions can lead to the exposure of sensitive configuration data or the integrity compromise of the licensing environment. With a CVSS score of 8.7, this vulnerability represents a high-severity risk that could result in significant operational instability or security configuration drift across affected appliance platforms.
Remediation
Immediate Action: Update the NVIDIA Delegated Licensing Service to version 3.5.1 or 3.1.7 immediately as specified in the official NVIDIA security bulletin.
Proactive Monitoring: Review system access logs for anomalous requests directed at the licensing service endpoint and monitor for unexpected changes to license configurations.
Compensating Controls: Restrict network access to the Delegated Licensing Service to only known, trusted administrative segments to limit the potential pool of attackers who could exploit this flaw.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for unauthorized actions within the licensing infrastructure, organizations should treat this vulnerability as a high priority. Ensure all affected NVIDIA appliances are updated to the recommended fixed versions to eliminate the risk of privilege misuse and information disclosure.