GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Riva: Unauthorized access to the speech service (insufficient access control)

CVE-2025-23242NVIDIA / GPU stackcurated

Impact

Unauthorized access to the speech service (insufficient access control)

Who can reach it

Network client of the Riva endpoint

What to do

Upgrade Riva NIM containers; redeploy; put auth in front of the endpoint

Fleet impact

How widespread

Common - shipped as a NIM-style microservice, deployed by neoclouds offering managed speech endpoints

Cost to remediate

daemon-restart (upgrade to Riva 2.19.0 and redeploy the service)

Why it hits the whole fleet

Improper access control in the service auth layer, network-reachable with no user interaction: an unauthenticated caller escalates privileges into the hosting cloud environment and can read other tenants' data

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.