Impact
NVIDIA ConnectX and BlueField devices contain an out‑of‑bounds write flaw (CWE‑787) in their command interface. A local user who has virtual‑function access can send crafted input that causes the device to write beyond a buffer boundary, allowing the attacker to execute arbitrary code on the NIC firmware.
Affected Systems
The flaw applies to all NVIDIA BlueField products – the General Availability release and the LTS22, LTS23, LTS24 editions – as well as all NVIDIA ConnectX products – the GA release and the LTS22 through LTS24 iterations. Specific firmware or driver versions are not enumerated, so any releases within those product families may be impacted.
Risk and Exploitability
The CVSS score of 9.0 indicates a high severity flaw. The EPSS score is below 1%, signaling a low probability of exploitation at present, and the vulnerability is not listed in CISA KEV. The likely attack vector is local and requires virtual‑function privileges on the NIC; exploiting the out‑of‑bounds write enables the attacker to run malicious code on the device.
OpenCVE Enrichment