Close Menu
World Forbes – Business, Tech, AI & Global Insights
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
What's Hot

More Pakistani women are joining the country’s firefighters

November 7, 2025

Musk’s Net Worth Drops $10 Billion—And Tesla Shares Fall—Here’s Why

November 7, 2025

Here’s what to know about a study that raises questions about melatonin use and heart health

November 7, 2025
Facebook X (Twitter) Instagram
Trending
  • More Pakistani women are joining the country’s firefighters
  • Musk’s Net Worth Drops $10 Billion—And Tesla Shares Fall—Here’s Why
  • Here’s what to know about a study that raises questions about melatonin use and heart health
  • Trump’s Bungled Bet On Bitcoin Is Costing Him Bigtime
  • A Startup Was Their First-Ever Job—Now They’re The World’s Youngest Self Made Billionaires
  • Meet The Former Journalist Giving Away Billions
  • Supermarket Billionaire Reacts To Mamdani’s Win
  • Farmers’ Almanac to cease publication after 2 centuries of predicting the weather
World Forbes – Business, Tech, AI & Global InsightsWorld Forbes – Business, Tech, AI & Global Insights
Saturday, November 8
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
World Forbes – Business, Tech, AI & Global Insights
Home » Nvidia Riva Vulnerabilities Allow Unauthorized Use of AI Services
Cybersecurity

Nvidia Riva Vulnerabilities Allow Unauthorized Use of AI Services

By adminMarch 17, 2025No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email
Post Views: 133


Nvidia recently patched a couple of Riva vulnerabilities that could allow hackers to abuse AI services.

Riva is a set of GPU-accelerated multilingual speech and translation services designed for building customizable, real-time conversational AI for large language models (LLMs) and retrieval-augmented generation (RAG).

A security advisory published by Nvidia on March 10 reveals that Riva is impacted by two improper access control issues. One of the flaws, tracked as CVE-2025-23242 and assigned a ‘high severity’ rating, can allow privilege escalation, data tapering, denial of service (DoS), and information disclosure.

The second vulnerability, CVE-2025-23243, is a medium-severity issue allowing data tampering and DoS attacks.

The security holes impact versions 2.18 and prior of Nvidia Riva on Linux. A patch is included in version 2.19.0.

The vulnerabilities were discovered by Trend Micro researchers and reported to Nvidia in November 2024. Trend Micro’s Zero Day Initiative has published individual advisories for CVE-2025-23242 and CVE-2025-23243, noting that they can both be exploited without authentication. 

Alfredo Oliveira, one of the Trend Micro security researchers credited for reporting these vulnerabilities, told SecurityWeek that while Riva instances should not be exposed to the internet, the research was actually triggered by the discovery of web-facing systems.

Oliveira explained that they have identified several vulnerable Riva instances exposed to the internet due to a misconfiguration that was caught by Trend Micro solutions.

Advertisement. Scroll to continue reading.

“The default cloud installation creates a network rule exposing the service to 0.0.0.0/0 (whole internet),” the researcher explained.

An attacker who finds a vulnerable Riva instance could use the associated service without authorization.

“Riva is an AI Speech service — it does translations, speech-to-text and text-to-speech generation, among other things. Both the license and infrastructure to run these are very expensive, abusing this system would cause a considerable financial impact,” Oliveira said.

Related: Chipmaker Patch Tuesday: Intel, AMD, Nvidia Fix High-Severity Vulnerabilities

Related: Nvidia, Zoom, Zyxel Patch High-Severity Vulnerabilities

Related: Nvidia Patches High-Severity Flaws in Windows, Linux Graphics Drivers



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

O2 Service Vulnerability Exposed User Location

May 20, 2025

Madhu Gottumukkala Officially Announced as CISA Deputy Director

May 20, 2025

BreachRx Lands $15 Million as Investors Bet on Breach-Workflow Software

May 19, 2025

Printer Company Procolored Served Infected Software for Months

May 19, 2025

UK Legal Aid Agency Finds Data Breach Following Cyberattack

May 19, 2025

480,000 Catholic Health Patients Impacted by Serviceaide Data Leak

May 19, 2025
Add A Comment
Leave A Reply

Don't Miss
Billionaires

Musk’s Net Worth Drops $10 Billion—And Tesla Shares Fall—Here’s Why

November 7, 2025

ToplineTesla shares declined more than 3% on Friday, cutting CEO Elon Musk’s fortune by $10…

Trump’s Bungled Bet On Bitcoin Is Costing Him Bigtime

November 7, 2025

A Startup Was Their First-Ever Job—Now They’re The World’s Youngest Self Made Billionaires

November 7, 2025

Meet The Former Journalist Giving Away Billions

November 7, 2025
Our Picks

More Pakistani women are joining the country’s firefighters

November 7, 2025

Musk’s Net Worth Drops $10 Billion—And Tesla Shares Fall—Here’s Why

November 7, 2025

Here’s what to know about a study that raises questions about melatonin use and heart health

November 7, 2025

Trump’s Bungled Bet On Bitcoin Is Costing Him Bigtime

November 7, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to World-Forbes.com
At World-Forbes.com, we bring you the latest insights, trends, and analysis across various industries, empowering our readers with valuable knowledge. Our platform is dedicated to covering a wide range of topics, including sports, small business, business, technology, AI, cybersecurity, and lifestyle.

Our Picks

After Klarna, Zoom’s CEO also uses an AI avatar on quarterly call

May 23, 2025

Anthropic CEO claims AI models hallucinate less than humans

May 22, 2025

Anthropic’s latest flagship AI sure seems to love using the ‘cyclone’ emoji

May 22, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 world-forbes. Designed by world-forbes.

Type above and press Enter to search. Press Esc to cancel.