Privilege Escalation Vulnerability in NVIDIA AIStore by NVIDIA
CVE-2025-23260

5MEDIUM

Key Information:

Vendor

Nvidia

Status
Vendor
CVE Published:
24 June 2025

What is CVE-2025-23260?

NVIDIA AIStore is affected by a vulnerability in the AIS Operator that allows users to achieve elevated access to Kubernetes (k8s) clusters. This could occur through exploiting the ServiceAccount linked with the ClusterRole. A successful exploitation of this flaw could potentially lead to unauthorized information disclosure, compromising sensitive data within the k8s environment.

Affected Version(s)

AIStore Kubernetes All versions prior 2.3.0

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.