CVE-2025-7673 – Zyxel VMG8825-T50K Firmware Vulnerability
July 18, 2025Multiple Sophos Intercept X Vulnerabilities
July 18, 2025CVE-2025-7673 – Zyxel VMG8825-T50K Firmware Vulnerability
July 18, 2025Multiple Sophos Intercept X Vulnerabilities
July 18, 2025Severity
Medium
Analysis Summary
CVE-2025-23267 CVSS:8.5
NVIDIA Container Toolkit is vulnerable to a denial of service, caused by a vulnerability in the update-ldcache hook.
CVE-2025-23269 CVSS:4.7
NVIDIA Jetson Linux contains a vulnerability in the kernel where an attacker may cause an exposure of sensitive information due to a shared microarchitectural predictor state that influences transient execution. A successful exploit of this vulnerability may lead to information disclosure.
CVE-2025-23270 CVSS:7.1
NVIDIA Jetson Linux contains a vulnerability in UEFI Management mode, where an unprivileged local attacker may cause exposure of sensitive information via a side channel vulnerability. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
CVE-2025-23266 CVSS:9
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.
CVE-2025-23263 CVSS:7.6
NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause escalation of privileges and denial of service on the VLAN.
Impact
- Information Disclosure
- Denial of Service
- Privileges Escalation
Indicators of Compromise
CVE
CVE-2025-23267
CVE-2025-23269
CVE-2025-23270
CVE-2025-23266
CVE-2025-23263
Affected Vendors
- NVIDIA
Affected Products
- NVIDIA NVIDIA Container Toolkit 1.17.7
- NVIDIA Jetson Orin Series All versions prior to JP6.x: 36.4.4
- NVIDIA Xavier Series All versions prior to JP5.x: 35.6.2
- NVIDIA GPU Operator 25.3.0
- NVIDIA DOCA-Host All versions prior to 2.5.4-0.0.9
- NVIDIA DOCA-Host All versions prior to 2.9.3-0.2.2
- NVIDIA DOCA-Host All versions prior to 3.0.0-058001
- NVIDIA Mellanox OFED All versions prior to 5.8-7.0.6.1
- NVIDIA Mellanox OFED All versions prior to 23.10-5.1.4.0
- NVIDIA Mellanox OFED All versions prior to 24.10-3.2.5.0
- NVIDIA Jetson Orin
- NVIDIA IGX Orin
- NVIDIA Xavier Devices
Remediation
Refer to NVIDIA Website for patch, upgrade, or suggested workaround information.