CVE-2025-33207Medium· 6.8▾ SunlitNVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register interface by sending a malicious command to the firmware. A successful exploit …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register interface by sending a malicious command to the firmware. A successful exploit of this vulnerability might lead to denial of service.
bluefield_ga All versions prior to 47.1020bluefield_lts23 All versions prior to 39.5124bluefield_lts24 All versions prior to 43.4100connectx_ga All versions prior to 47.1020connectx_lts23 All versions prior to 39.5124connectx_lts24 All versions prior to 43.4100ConnectX-5 All versions prior to 16.35.8008Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-65102High· 7.8NVIDIA DeepStream contains a vulnerability where an attacker could cause an integer overflow by supplying crafted tensor dimensions in a YAML configuration file
CVE-2026-24239High· 7.8NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious data created by an attacker could cause remote code execution
CVE-2026-65111High· 7.8NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection
CVE-2026-24267High· 7.8NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer component, where malicious data created by an attacker could cause remote code execution
CVE-2026-65179High· 8.8NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacker-controlled .pkl file via pickle.load() without validation
CVE-2026-65178High· 7.8NVIDIA NeMo contains a vulnerability in its dataset-loading workflow where a maliciously crafted model_config.yaml can inject unsafe parameters