CVE-2025-33207
MEDIUM
6,8
Source: [email protected]
Attack Vector: adjacent_network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: changed
Confidentiality: none
Integrity: none
Availability: high
Description
AI Translation Available
NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register interface by sending a malicious command to the firmware. A successful exploit of this vulnerability might lead to denial of service.
1262
Improper Access Control for Register Interface
StableCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Potential Impacts:
Read Memory
Read Application Data
Modify Memory
Modify Application Data
Gain Privileges Or Assume Identity
Bypass Protection Mechanism
Unexpected State
Alter Execution Logic
Applicable Platforms
All platforms may be affected
https://github.com/NVIDIA/product-security/tree/main/2026/5847
https://nvd.nist.gov/vuln/detail/CVE-2025-33207
https://www.cve.org/CVERecord?id=CVE-2025-33207