CVE-2026-24166

Summary

NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-coded cryptographic key to extract information. A successful exploit of this vulnerability might lead to information disclosure and escalation of privileges.

Affected Software

VendorProductVersion RangeStatus
NVIDIAUnified Fabric Manager Enterprise - GAAll GA versions prior to 6.24.1-5affected
NVIDIAUnified Fabric Manager Enterprise - LTS 2025All LTS versions prior to 6.23.20-3affected
NVIDIAUnified Fabric Manager Enterprise - LTS 2024All LTS versions prior to 6.19.15affected
NVIDIAUnified Fabric Manager Enterprise - LTS 2023All LTS versions prior to 6.15.17affected

Weaknesses

  • CWE-321: CWE-321 Use of Hard-coded Cryptographic Key

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References