Impact
NVIDIA Unified Fabric Manager Enterprise was found to allow code injection through its plugin management API. An authenticated user with low privileges can send a specially crafted API request that bypasses input validation, allowing arbitrary code to be injected. This flaw can result in code execution, privilege escalation, and information disclosure for the compromised system.
Affected Systems
The vulnerability affects all variants of NVIDIA Unified Fabric Manager Enterprise, including the General Availability and the LTS releases for 2023, 2024, and 2025. The affected components are the plugin management interface exposed by the UFM Enterprise service.
Risk and Exploitability
The CVSS score of 8 indicates a high severity of this flaw. With no EPSS score available, there is insufficient data to assess current exploitation likelihood, but the potential for local code execution and privilege escalation is significant for authenticated users. The flaw is not yet listed in the CISA KEV catalog, yet its impact warrants prompt remediation. The likely attack path requires the attacker to authenticate with a low‑privilege account against the UFM service, then issue a malicious plugin load request.
OpenCVE Enrichment