


Perceptive Security
SOC/SIEM Consultancy

NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bou…
Published:
30 juni 2026 om 22:00:00
Alert date:
1 juli 2026 om 17:07:03
Source:
nvd.nist.gov
Network Infrastructure, Cloud & Virtualization, Zero-Day Vulnerabilities
CVE-2025-23350 affects NVIDIA ConnectX and BlueField network adapters, exposing a vulnerability in the command interface. A local user with virtual function (VF) access can trigger a write out-of-bounds condition via crafted input. Successful exploitation may result in arbitrary code execution on the affected device. The vulnerability requires local access with VF privileges, limiting remote exploitation but still posing significant risk in virtualized and multi-tenant environments. NVIDIA has published a security advisory addressing this issue. The flaw is categorized as high severity given its potential for arbitrary code execution. It primarily impacts data center and high-performance networking hardware commonly used in cloud and enterprise infrastructure.
Technical details
Mitigation steps:
Affected products:
NVIDIA ConnectX
NVIDIA BlueField
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-23350
https://github.com/NVIDIA/product-security/tree/main/2026/5699
https://www.cve.org/CVERecord?id=CVE-2025-23350
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
