CVE-2025-23243 is a critical improper access control vulnerability in NVIDIA Riva, affecting both the NVIDIA Riva and Linux kernel products. This flaw allows an unauthenticated attacker to remotely cause data tampering or a denial of service, as indicated by its CVSS score of 9.1. While the vulnerability has a high FAUCET Risk Score of 84/100 and has garnered some media attention, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB) and it is not listed in the KEV catalog. Community discussion is minimal, suggesting it is not yet widely exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.19.0CPE matchmatch criteria | cpe:2.3:a:nvidia:riva:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.