top of page
perceptive_background_267k.jpg

NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bou…

Published:

30 juni 2026 om 22:00:00

Alert date:

1 juli 2026 om 17:07:03

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Cloud & Virtualization, Zero-Day Vulnerabilities

CVE-2025-23350 affects NVIDIA ConnectX and BlueField network adapters, exposing a vulnerability in the command interface. A local user with virtual function (VF) access can trigger a write out-of-bounds condition via crafted input. Successful exploitation may result in arbitrary code execution on the affected device. The vulnerability requires local access with VF privileges, limiting remote exploitation but still posing significant risk in virtualized and multi-tenant environments. NVIDIA has published a security advisory addressing this issue. The flaw is categorized as high severity given its potential for arbitrary code execution. It primarily impacts data center and high-performance networking hardware commonly used in cloud and enterprise infrastructure.

Technical details

Mitigation steps:

Affected products:

NVIDIA ConnectX
NVIDIA BlueField

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page