NVIDIA Riva: Unauthorized access to the speech service (insufficient access control)
CVE-2025-23242NVIDIA / GPU stackcurated
Impact
Unauthorized access to the speech service (insufficient access control)
Who can reach it
Network client of the Riva endpoint
What to do
Upgrade Riva NIM containers; redeploy; put auth in front of the endpoint
Fleet impact
How widespread
Common - shipped as a NIM-style microservice, deployed by neoclouds offering managed speech endpoints
Cost to remediate
daemon-restart (upgrade to Riva 2.19.0 and redeploy the service)
Why it hits the whole fleet
Improper access control in the service auth layer, network-reachable with no user interaction: an unauthenticated caller escalates privileges into the hosting cloud environment and can read other tenants' data
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.