cbcvebase.
CVE-2023-25519
published 2023-09-12

CVE-2023-25519: NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit contains a vulnerability where a restricted host may cause an incorrect user management…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit contains a vulnerability where a restricted host may cause an incorrect user management error. A successful exploit of this vulnerability may lead to escalation of privileges.

Affected

8 ranges
VendorProductVersion rangeFixed in
nvidiabluefield_1
nvidiabluefield_1_firmware>= 18.24.1000
nvidiabluefield_2_ga
nvidiabluefield_2_ga_firmware< 24.38.100224.38.1002
nvidiabluefield_2_lts
nvidiabluefield_2_lts_firmware< 24.35.300624.35.3006
nvidiabluefield_3_ga
nvidiabluefield_3_ga_firmware< 32.38.100232.38.1002