NVIDIA ConnectX Incorrect Authorization Vulnerability in Management Interface

Vulnerability

A vulnerability exists in the management interface of NVIDIA ConnectX products, specifically in versions prior to 45.1020, 35.4554, 39.5050, and 43.3608, as well as in ConnectX-4 and ConnectX-4 LX versions prior to 12.28.4704 and 14.32.1908, respectively. This vulnerability allows an attacker with local access to manipulate authorization processes, potentially leading to unauthorized configuration changes. Exploitation of this issue could result in a denial-of-service, unauthorized privilege escalation, information disclosure, and data tampering.

Impact

Exploitation of this vulnerability could cause a denial-of-service, unauthorized privilege escalation, information disclosure, and data tampering.

Remediation

Users are advised to update to version 45.1020 for ConnectX GA products, version 35.4554 for ConnectX LTS22, version 39.5050 for ConnectX LTS23, and version 43.3608 for ConnectX LTS24. For ConnectX-4 and ConnectX-4 LX, versions 12.28.4704 and 14.32.1908 will be published by the end of September.

Added: Sep 4, 2025, 6:29 PM
Updated: Sep 4, 2025, 6:29 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
3.8
exploitability
3.5
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.