NVIDIA BlueField Privilege Escalation Vulnerability in Management Interface

Vulnerability

A vulnerability exists in the management interface of NVIDIA BlueField products, specifically in BlueField-2 and BlueField-3 platforms. This vulnerability allows an attacker with local access to manipulate authorization processes, potentially leading to unauthorized configuration changes. Exploitation of this issue could result in a denial-of-service, unauthorized privilege escalation, information disclosure, and unauthorized data modification.

Impact

Successful exploitation could cause a denial-of-service, unauthorized privilege escalation, information disclosure, and unauthorized data modification.

Remediation

Users are advised to update to version 45.1020 for BlueField GA, version 35.4554 for BlueField LTS22, and version 39.5050 for BlueField LTS23. For BlueField LTS24, version 43.3608 is recommended.

Added: Sep 4, 2025, 7:56 PM
Updated: Sep 4, 2025, 7:56 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
3.5
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.