Skip to content
NvidiaCVE-2025-33207

Nvidia BlueField GA: improper access control

Medium6.8CVE-2025-33207 · Published Sep 29, 2026

NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register interface by sending a malicious command to the firmware. A successful exploit of this vulnerability might lead to denial of service.

Nvidia advisory

Affected versions

PackageAffectedFixed in
BlueField GA
Product
<= All versions prior to 47.1020No fix yet
BlueField LTS23
Product
<= All versions prior to 39.5124No fix yet
BlueField LTS24
Product
<= All versions prior to 43.4100No fix yet
ConnectX GA
Product
<= All versions prior to 47.1020No fix yet
ConnectX LTS23
Product
<= All versions prior to 39.5124No fix yet
ConnectX LTS24
Product
<= All versions prior to 43.4100No fix yet
ConnectX-5
Product
<= All versions prior to 16.35.8008No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-1262

More Nvidia advisories

All Nvidia
Advisory
Nvidia GeForce: code execution
High7.8Sep 30
Nvidia Virtual GPU Manager: code execution
High7.8Sep 30
Nvidia GeForce: improper access control
Medium5.5Sep 30
Nvidia GeForce: code execution
High7.8Sep 30
Nvidia GeForce: code execution
High7.8Sep 30
Nvidia DeepStream: integer overflow
High7.8Sep 29

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.