Status: UPDATED
| Advisory ID: CVE-2025-33255
Key Details
| CVE | CVE-2025-33255 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-09-24 |
| CVSS Vector | CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
| CVSS Prose | attack vector is local; attack complexity is high; privileges required is high; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | nvidia TensorRT-LLM |
| Classified as | CWE-502 (Deserialization of Untrusted Data) |
| Exploitation prediction (EPSS) | 0.57% probability of exploitation in the next 30 days (45% percentile) -- FIRST.org's EPSS model. |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.
What to Do
Monitor nvidia's web page for any future patch releases. See vendor advisory link below.
References