CVE-2025-33207 PUBLISHED

Assigner: nvidia
Reserved: 15.04.2025 Published: 29.09.2026 Updated: 29.09.2026

NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register interface by sending a malicious command to the firmware. A successful exploit of this vulnerability might lead to denial of service.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CVSS Score: 6.8

Product Status

Vendor NVIDIA
Product BlueField GA
Versions Default: unaffected
  • Version All versions prior to 47.1020 is affected
Vendor NVIDIA
Product BlueField LTS23
Versions Default: unaffected
  • Version All versions prior to 39.5124 is affected
Vendor NVIDIA
Product BlueField LTS24
Versions Default: unaffected
  • Version All versions prior to 43.4100 is affected
Vendor NVIDIA
Product ConnectX GA
Versions Default: unaffected
  • Version All versions prior to 47.1020 is affected
Vendor NVIDIA
Product ConnectX LTS23
Versions Default: unaffected
  • Version All versions prior to 39.5124 is affected
Vendor NVIDIA
Product ConnectX LTS24
Versions Default: unaffected
  • Version All versions prior to 43.4100 is affected
Vendor NVIDIA
Product ConnectX-5
Versions Default: unaffected
  • Version All versions prior to 16.35.8008 is affected

References

Problem Types

  • CWE-1262 Improper Access Control for Register Interface CWE

Impacts

  • denial of service