CVE-2025-23356

8.4

NVIDIA · Isaac Lab

NVIDIA Isaac Lab contains an authentication bypass vulnerability in SB3 configuration parsing that may lead to code execution, denial of service, privilege escalation, or data tampering.

Executive summary

A critical vulnerability in NVIDIA Isaac Lab allows unauthenticated attackers to potentially achieve remote code execution, privilege escalation, or data tampering.

Vulnerability

The vulnerability stems from a flaw in SB3 configuration parsing, identified as a missing authentication check (CWE-306). An unauthenticated attacker can exploit this flaw to execute arbitrary code or compromise system integrity.

Business impact

The potential for code execution and privilege escalation presents a severe risk to organizational infrastructure, as it allows attackers to gain full control over affected systems. With a CVSS score of 8.4, this vulnerability is classified as High, reflecting the significant impact on confidentiality, integrity, and availability if successfully exploited.

Remediation

Immediate Action: Update NVIDIA Isaac Lab to version 2.2.1 or later to resolve the configuration parsing flaw.

Proactive Monitoring: Monitor system logs for unauthorized configuration changes or unusual process execution patterns that deviate from standard Isaac Lab operations.

Compensating Controls: Ensure the application is deployed within a restricted network segment with strict access controls to limit exposure to untrusted entities.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

The severity of this vulnerability necessitates immediate action. Administrators must prioritize updating NVIDIA Isaac Lab to the latest version to remediate the underlying authentication bypass, thereby preventing potential system compromise and unauthorized data access.

More NVIDIA CVEs

Sources