Vulnerability in NVIDIA ConnectX and BlueField Command Interface
CVE-2025-23350

9CRITICAL

Key Information:

Vendor

Nvidia

Vendor
CVE Published:
1 July 2026

What is CVE-2025-23350?

NVIDIA ConnectX and BlueField products are susceptible to a command interface vulnerability that permits local users with virtual function access to exploit a write out-of-bounds condition through crafted input. If successfully exploited, this vulnerability could allow an attacker to execute arbitrary code on the affected device, potentially compromising its integrity and functionality.

Affected Version(s)

BlueField GA BlueField-2(46) All versions prior to 46.3008

BlueField LTS22 BlueField-2(35) All versions prior to 35.8002

BlueField LTS23 BlueField-2(39) All versions prior to 39.8002

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.