CVE-2025-33207

Summary

NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register interface by sending a malicious command to the firmware. A successful exploit of this vulnerability might lead to denial of service.

Affected Software

VendorProductVersion RangeStatus
NVIDIABlueField GAAll versions prior to 47.1020affected
NVIDIABlueField LTS23All versions prior to 39.5124affected
NVIDIABlueField LTS24All versions prior to 43.4100affected
NVIDIAConnectX GAAll versions prior to 47.1020affected
NVIDIAConnectX LTS23All versions prior to 39.5124affected
NVIDIAConnectX LTS24All versions prior to 43.4100affected
NVIDIAConnectX-5All versions prior to 16.35.8008affected

Weaknesses

  • CWE-1262: CWE-1262 Improper Access Control for Register Interface

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References