CVE-2025-23295

NVIDIA Apex for all platforms contains a vulnerability in a Python component where an attacker could cause a code injection issue by providing a malicious file. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nvidia:apex:*:*:*:*:*:*:*:*

History

22 Oct 2025, 18:35

Type Values Removed Values Added
First Time Nvidia apex
Nvidia
References () https://nvd.nist.gov/vuln/detail/CVE-2025-23295 - () https://nvd.nist.gov/vuln/detail/CVE-2025-23295 - Technical Description
References () https://nvidia.custhelp.com/app/answers/detail/a_id/5680 - () https://nvidia.custhelp.com/app/answers/detail/a_id/5680 - Vendor Advisory
References () https://www.cve.org/CVERecord?id=CVE-2025-23295 - () https://www.cve.org/CVERecord?id=CVE-2025-23295 - Technical Description
CPE cpe:2.3:a:nvidia:apex:*:*:*:*:*:*:*:*

14 Aug 2025, 13:12

Type Values Removed Values Added
Summary
  • (es) NVIDIA Apex para todas las plataformas contiene una vulnerabilidad en un componente de Python que permite a un atacante causar un problema de inyección de código al proporcionar un archivo malicioso. Una explotación exitosa de esta vulnerabilidad podría provocar la ejecución de código, la escalada de privilegios, la divulgación de información y la manipulación de datos.

13 Aug 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-13 18:15

Updated : 2025-10-22 18:35


NVD link : CVE-2025-23295

Mitre link : CVE-2025-23295

CVE.ORG link : CVE-2025-23295


JSON object : View

Products Affected

nvidia

  • apex
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')