High severity7.8NVD Advisory· Published Sep 12, 2023· Updated Jun 17, 2026
CVE-2023-25519
CVE-2023-25519
Description
NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit contains a vulnerability where a restricted host may cause an incorrect user management error. A successful exploit of this vulnerability may lead to escalation of privileges.
Affected products
9- cpe:2.3:o:nvidia:bluefield_2_ga_firmware:*:*:*:*:*:*:*:*Range: <24.38.1002
- cpe:2.3:o:nvidia:bluefield_2_lts_firmware:*:*:*:*:*:*:*:*Range: <24.35.3006
- cpe:2.3:o:nvidia:bluefield_3_ga_firmware:*:*:*:*:*:*:*:*Range: <32.38.1002
Patches
Vulnerability mechanics
References
2- nvidia.custhelp.com/app/answers/detail/a_id/5479nvdVendor Advisory
- https//nvidia.custhelp.com/app/answers/detail/a_id/5479nvdBroken Link
News mentions
0No linked articles in our index yet.