6.8
CVE-2025-33207
- EPSS 0.15%
- Veröffentlicht 29.09.2026 15:17:12
- Zuletzt bearbeitet 29.09.2026 21:27:41
- Erkennungen
NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register interface by sending a malicious command to the firmware. A successful exploit of this vulnerability might lead to denial of service.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerNVIDIA
≫
Produkt
BlueField GA
Default Statusunaffected
Version
All versions prior to 47.1020
Status
affected
HerstellerNVIDIA
≫
Produkt
BlueField LTS23
Default Statusunaffected
Version
All versions prior to 39.5124
Status
affected
HerstellerNVIDIA
≫
Produkt
BlueField LTS24
Default Statusunaffected
Version
All versions prior to 43.4100
Status
affected
HerstellerNVIDIA
≫
Produkt
ConnectX GA
Default Statusunaffected
Version
All versions prior to 47.1020
Status
affected
HerstellerNVIDIA
≫
Produkt
ConnectX LTS23
Default Statusunaffected
Version
All versions prior to 39.5124
Status
affected
HerstellerNVIDIA
≫
Produkt
ConnectX LTS24
Default Statusunaffected
Version
All versions prior to 43.4100
Status
affected
HerstellerNVIDIA
≫
Produkt
ConnectX-5
Default Statusunaffected
Version
All versions prior to 16.35.8008
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.037 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Nvidia | 6.8 | 2.3 | 4 |
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
|
CWE-1262 Improper Access Control for Register Interface
The product uses memory-mapped I/O registers that act as an interface to hardware functionality from software, but there is improper access control to those registers.
https://github.com/NVIDIA/product-security/tree/main/2026/5847
https://nvd.nist.gov/vuln/detail/CVE-2025-33207
https://www.cve.org/CVERecord?id=CVE-2025-33207