CVE-2025-33207
Received
Received - Intake
Improper Access Control in NVIDIA ConnectX and Bluefield Firmware
Vulnerability report for CVE-2025-33207, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-29
Last updated on: 2026-09-29
Assigner: NVIDIA Corporation
Description
Description
NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register interface by sending a malicious command to the firmware. A successful exploit of this vulnerability might lead to denial of service.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nvidia | connectx | * |
| nvidia | bluefield | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1262 | The product uses memory-mapped I/O registers that act as an interface to hardware functionality from software, but there is improper access control to those registers. |