VYPR

ConnectX

by Nvidia

CVEs (7)

  • CVE-2025-23299MedOct 22, 2025
    risk 0.44cvss 6.7epss 0.00

    NVIDIA Bluefield and ConnectX contain a vulnerability in the management interface that could allow a malicious actor with high privilege access to execute arbitrary code.

  • CVE-2023-0204MedApr 22, 2023
    risk 0.42cvss 6.5epss 0.00

    NVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX contain a vulnerability in the NIC firmware, where an unprivileged user can cause improper handling of exceptional conditions, which may lead to denial of service.

  • CVE-2025-23262MedSep 4, 2025
    risk 0.41cvss 6.3epss 0.00

    NVIDIA ConnectX contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modify the configuration. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges,…

  • CVE-2023-0205MedApr 22, 2023
    risk 0.33cvss 5.0epss 0.01

    NVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX contain a vulnerability in the NIC firmware, where an unprivileged user can exploit insufficient granularity of access control, which may lead to denial of service.

  • CVE-2023-0203MedApr 22, 2023
    risk 0.33cvss 5.0epss 0.01

    NVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX contain a vulnerability in the NIC firmware, where an unprivileged user can exploit insufficient granularity of access control, which may lead to denial of service.

  • CVE-2025-23351CriJul 1, 2026
    risk 0.00cvss 9.0epss 0.00

    NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device.

  • CVE-2025-23350CriJul 1, 2026
    risk 0.00cvss 9.0epss 0.00

    NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device.