Access Control Flaw in NVIDIA ConnectX and Bluefield Firmware
CVE-2025-33207

6.8MEDIUM

Key Information:

Vendor

Nvidia

Vendor
CVE Published:
29 September 2026

What is CVE-2025-33207?

NVIDIA ConnectX and Bluefield products are susceptible to an improper access control vulnerability within a specific control register. This flaw allows a user with virtual function (VF) access to execute malicious commands targeting the firmware, potentially leading to denial of service. Exploitation of this vulnerability could disrupt normal operations and compromise system integrity.

Affected Version(s)

BlueField GA BlueField-2 All versions prior to 47.1020

BlueField LTS23 BlueField-2 All versions prior to 39.5124

BlueField LTS24 BlueField-2 All versions prior to 43.4100

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.