CVE-2025-33180: Command Injection
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit of this vulnerability might lead to escalation of privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33180?
CVE-2025-33180 has a high severity rating due to the potential privilege escalation it allows.
How do I fix CVE-2025-33180?
To fix CVE-2025-33180, it is recommended to update the affected NVIDIA Cumulus Linux and NVOS products to the latest patched versions.
What are the affected products for CVE-2025-33180?
CVE-2025-33180 affects NVIDIA Cumulus Linux versions up to 5.14.0 and NVOS versions up to 25.02.4282.
Who is affected by CVE-2025-33180?
Low-privileged users of NVIDIA Cumulus Linux and NVOS products may be affected by CVE-2025-33180, as they could potentially exploit the vulnerability.
What type of vulnerability is CVE-2025-33180?
CVE-2025-33180 is a command injection vulnerability in the NVUE interface that could lead to privilege escalation.