CVE-2025-23317

NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shell by sending a specially crafted HTTP request. A successful exploit of this vulnerability might lead to remote code execution, denial of service, data tampering, or information disclosure.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:nvidia:triton_inference_server:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

12 Aug 2025, 16:34

Type Values Removed Values Added
Summary
  • (es) NVIDIA Triton Inference Server contiene una vulnerabilidad en el servidor HTTP, donde un atacante podría iniciar un shell inverso mediante el envío de una solicitud HTTP especialmente manipulada. Una explotación exitosa de esta vulnerabilidad podría provocar ejecución remota de código, denegación de servicio, manipulación de datos o divulgación de información.
References () https://nvd.nist.gov/vuln/detail/CVE-2025-23317 - () https://nvd.nist.gov/vuln/detail/CVE-2025-23317 - US Government Resource
References () https://nvidia.custhelp.com/app/answers/detail/a_id/5687 - () https://nvidia.custhelp.com/app/answers/detail/a_id/5687 - Vendor Advisory
References () https://www.cve.org/CVERecord?id=CVE-2025-23317 - () https://www.cve.org/CVERecord?id=CVE-2025-23317 - Third Party Advisory
CPE cpe:2.3:a:nvidia:triton_inference_server:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
First Time Nvidia
Linux
Nvidia triton Inference Server
Microsoft
Microsoft windows
Linux linux Kernel

06 Aug 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-06 13:15

Updated : 2025-08-12 16:34


NVD link : CVE-2025-23317

Mitre link : CVE-2025-23317

CVE.ORG link : CVE-2025-23317


JSON object : View

Products Affected

microsoft

  • windows

linux

  • linux_kernel

nvidia

  • triton_inference_server
CWE
CWE-122

Heap-based Buffer Overflow