Impact
A flaw in the session management component of NVIDIA Unified Fabric Manager Enterprise allows an attacker to exploit a hard‑coded cryptographic key. This can lead to the extraction of sensitive session data, resulting in both information disclosure and the potential for privileges to be escalated beyond intended limits.
Affected Systems
NVIDIA Unified Fabric Manager Enterprise Enterprise GA and the LTS releases of 2023, 2024, and 2025 are affected.
Risk and Exploitability
The vulnerability has a CVSS score of 5.1, indicating moderate impact. Exploitation is likely possible when the attacker gains network access to the UFM management interface, which is the presumed attack vector; however, the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. If successfully exploited, the attacker could read confidential data and elevate privileges within the fabric manager, but the lack of public exploit evidence suggests that the risk is primarily theoretical at this time.
OpenCVE Enrichment