CVE-2025-23317

NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shell by sending a specially crafted HTTP request. A successful exploit of this vulnerability might lead to remote code execution, denial of service, data tampering, or information disclosure.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:nvidia:triton_inference_server:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

12 Aug 2025, 16:34

Type Values Removed Values Added
Summary
  • (es) NVIDIA Triton Inference Server contiene una vulnerabilidad en el servidor HTTP, donde un atacante podría iniciar un shell inverso mediante el envío de una solicitud HTTP especialmente manipulada. Una explotación exitosa de esta vulnerabilidad podría provocar ejecución remota de código, denegación de servicio, manipulación de datos o divulgación de información.
References () https://nvd.nist.gov/vuln/detail/CVE-2025-23317 - () https://nvd.nist.gov/vuln/detail/CVE-2025-23317 - US Government Resource
References () https://nvidia.custhelp.com/app/answers/detail/a_id/5687 - () https://nvidia.custhelp.com/app/answers/detail/a_id/5687 - Vendor Advisory
References () https://www.cve.org/CVERecord?id=CVE-2025-23317 - () https://www.cve.org/CVERecord?id=CVE-2025-23317 - Third Party Advisory
First Time Microsoft
Nvidia
Nvidia triton Inference Server
Linux
Microsoft windows
Linux linux Kernel
CPE cpe:2.3:a:nvidia:triton_inference_server:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

06 Aug 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-06 13:15

Updated : 2025-08-12 16:34


NVD link : CVE-2025-23317

Mitre link : CVE-2025-23317

CVE.ORG link : CVE-2025-23317


JSON object : View

Products Affected

linux

  • linux_kernel

nvidia

  • triton_inference_server

microsoft

  • windows
CWE
CWE-122

Heap-based Buffer Overflow