Session Management Vulnerability in NVIDIA UFM Enterprise
CVE-2026-24166

5.1MEDIUM

What is CVE-2026-24166?

NVIDIA UFM Enterprise is affected by a vulnerability in its session management component, allowing attackers to utilize a hard-coded cryptographic key. This flaw can lead to unauthorized information disclosure and potential escalation of user privileges, significantly compromising the integrity of the system. It is essential for users and administrators to take appropriate measures to mitigate this risk by updating to the latest version and applying necessary security patches.

Affected Version(s)

Unified Fabric Manager Enterprise - GA UFM Enterprise Appliance, UFM XDR Enterprise Appliance All GA versions prior to 6.24.1-5

Unified Fabric Manager Enterprise - LTS 2023 UFM Enterprise Appliance, UFM XDR Enterprise Appliance All LTS versions prior to 6.15.17

Unified Fabric Manager Enterprise - LTS 2024 UFM Enterprise Appliance, UFM XDR Enterprise Appliance All LTS versions prior to 6.19.15

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.