Rewterz
CVE-2025-7673 – Zyxel VMG8825-T50K Firmware Vulnerability
July 18, 2025
Rewterz
Multiple Sophos Intercept X Vulnerabilities
July 18, 2025

Multiple NVIDIA Products Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2025-23267 CVSS:8.5

NVIDIA Container Toolkit is vulnerable to a denial of service, caused by a vulnerability in the update-ldcache hook.

CVE-2025-23269 CVSS:4.7

NVIDIA Jetson Linux contains a vulnerability in the kernel where an attacker may cause an exposure of sensitive information due to a shared microarchitectural predictor state that influences transient execution. A successful exploit of this vulnerability may lead to information disclosure.

CVE-2025-23270 CVSS:7.1

NVIDIA Jetson Linux contains a vulnerability in UEFI Management mode, where an unprivileged local attacker may cause exposure of sensitive information via a side channel vulnerability. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.

CVE-2025-23266 CVSS:9

NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.

CVE-2025-23263 CVSS:7.6

NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause escalation of privileges and denial of service on the VLAN.

Impact

  • Information Disclosure
  • Denial of Service
  • Privileges Escalation

Indicators of Compromise

CVE

  • CVE-2025-23267

  • CVE-2025-23269

  • CVE-2025-23270

  • CVE-2025-23266

  • CVE-2025-23263

Affected Vendors

  • NVIDIA

Affected Products

  • NVIDIA NVIDIA Container Toolkit 1.17.7
  • NVIDIA Jetson Orin Series All versions prior to JP6.x: 36.4.4
  • NVIDIA Xavier Series All versions prior to JP5.x: 35.6.2
  • NVIDIA GPU Operator 25.3.0
  • NVIDIA DOCA-Host All versions prior to 2.5.4-0.0.9
  • NVIDIA DOCA-Host All versions prior to 2.9.3-0.2.2
  • NVIDIA DOCA-Host All versions prior to 3.0.0-058001
  • NVIDIA Mellanox OFED All versions prior to 5.8-7.0.6.1
  • NVIDIA Mellanox OFED All versions prior to 23.10-5.1.4.0
  • NVIDIA Mellanox OFED All versions prior to 24.10-3.2.5.0
  • NVIDIA Jetson Orin
  • NVIDIA IGX Orin
  • NVIDIA Xavier Devices

Remediation

Refer to NVIDIA Website for patch, upgrade, or suggested workaround information.

CVE-2025-23267

CVE-2025-23269

CVE-2025-23270

CVE-2025-23266

CVE-2025-23263