Impact
NVIDIA Unified Fabric Manager Enterprise contains a command‑injection flaw in its user‑management component. A crafted API request can inject operating‑system commands when processed with administrator privileges, allowing the attacker to achieve arbitrary code execution, elevate privileges, and disclose sensitive information. The weakness maps to CWE‑77, denoting unsafe command execution based on user input.
Affected Systems
Vulnerable releases of NVIDIA Unified Fabric Manager Enterprise include the General Availability version and the LTS 2023, LTS 2024, and LTS 2025 editions. No specific patch level is enumerated in the advisory, so all supplied versions are considered affected until a fix is applied.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate severity that can be exploited by an authenticated administrator. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to have administrative credentials and to send a crafted API request to the user‑management endpoint. Once executed, the attacker gains full control of the system and can compromise confidentiality, integrity, and availability of the host and related infrastructure.
OpenCVE Enrichment