6.8

CVE-2025-33207

NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register interface by sending a malicious command to the firmware. A successful exploit of this vulnerability might lead to denial of service.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerNVIDIA
≫
Produkt BlueField GA
Default Statusunaffected
Version All versions prior to 47.1020
Status affected
HerstellerNVIDIA
≫
Produkt BlueField LTS23
Default Statusunaffected
Version All versions prior to 39.5124
Status affected
HerstellerNVIDIA
≫
Produkt BlueField LTS24
Default Statusunaffected
Version All versions prior to 43.4100
Status affected
HerstellerNVIDIA
≫
Produkt ConnectX GA
Default Statusunaffected
Version All versions prior to 47.1020
Status affected
HerstellerNVIDIA
≫
Produkt ConnectX LTS23
Default Statusunaffected
Version All versions prior to 39.5124
Status affected
HerstellerNVIDIA
≫
Produkt ConnectX LTS24
Default Statusunaffected
Version All versions prior to 43.4100
Status affected
HerstellerNVIDIA
≫
Produkt ConnectX-5
Default Statusunaffected
Version All versions prior to 16.35.8008
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.037
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Nvidia 6.8 2.3 4
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CWE-1262 Improper Access Control for Register Interface

The product uses memory-mapped I/O registers that act as an interface to hardware functionality from software, but there is improper access control to those registers.

https://github.com/NVIDIA/product-security/tree/main/2026/5847
https://nvd.nist.gov/vuln/detail/CVE-2025-33207
https://www.cve.org/CVERecord?id=CVE-2025-33207