VYPR

UFM Enterprise

by Nvidia

CVEs (6)

  • CVE-2026-24170HigAug 25, 2026
    risk 0.57cvss 8.8epss 0.00

    NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticated user could cause improper authentication by sending specially crafted HTTP requests. A successful exploit of this vulnerability might lead to code execution and…

  • CVE-2024-0130HigDec 6, 2024
    risk 0.57cvss 8.8epss 0.00

    NVIDIA UFM Enterprise, UFM Appliance, and UFM CyberAI contain a vulnerability where an attacker can cause an improper authentication issue by sending a malformed request through the Ethernet management interface. A successful exploit of this vulnerability might lead to…

  • CVE-2026-24169HigAug 25, 2026
    risk 0.52cvss 8.0epss 0.00

    NVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated user with low privileges could inject code by sending a specially crafted API request. A successful exploit of this vulnerability might lead to code execution, escalation of…

  • CVE-2026-24168MedAug 25, 2026
    risk 0.44cvss 6.8epss 0.01

    NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker with administrative privileges may cause command injection by sending crafted API requests. A successful exploit of this vulnerability may lead to code execution, escalation of…

  • CVE-2026-24167MedAug 25, 2026
    risk 0.44cvss 6.8epss 0.00

    NVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authenticated administrator could inject commands by sending a crafted API request. A successful exploit of this vulnerability might lead to code execution, escalation of privileges and…

  • CVE-2026-24166MedAug 25, 2026
    risk 0.33cvss 5.1epss 0.00

    NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-coded cryptographic key to extract information. A successful exploit of this vulnerability might lead to information disclosure and escalation of privileges.