CVE-2025-33207: Medium severity Nvidia ConnectX vulnerability
NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register interface by sending a malicious command to the firmware. A successful exploit of this vulnerability might lead to denial of service.
Affected Software
Event History
Frequently Asked Questions
Who is in a position to exploit this issue?
An attacker needs access to a virtual function (VF) on an affected NVIDIA ConnectX or BlueField device. The attack is adjacent-network reachable and requires low privileges; no user interaction is required.
What is the expected impact of successful exploitation?
Successful exploitation may cause a denial of service. The provided information does not indicate confidentiality or integrity impact.
What attacker action triggers the vulnerability?
The attacker sends a malicious command to the device firmware, targeting the vulnerable control-register interface and causing improper access control.