Impact
NVIDIA Unified Fabric Manager Enterprise’s web interface includes an improper authentication flaw that allows an authenticated user to send specially crafted HTTP requests, leading the system to grant elevated privileges or execute arbitrary code. The flaw is classified as CWE-287, an improper authentication vulnerability, and offers a pathway for attackers to compromise the managed fabric environment.
Affected Systems
The vulnerability affects NVIDIA Unified Fabric Manager Enterprise for all supported releases: the General Availability (GA) build and the LTS 2023, LTS 2024, and LTS 2025 editions.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. Although the EPSS score is not available, the flaw requires pre‑authenticated access, meaning it is most relevant to insiders or attackers who have obtained user credentials. Because exploitation can result in code execution, the risk is significant. The vulnerability is not currently listed in the CISA KEV catalog, but its high impact warrants prompt attention. Attackers would likely target the web interface and send crafted requests to trigger the improper authentication.
OpenCVE Enrichment