Back to Database
Status published
Critical
CVE-2025-23351
NVIDIA ConnectX and BlueField contain a vulnerability in the command...
Vulnerability Description
NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-23351
Credits & Attribution
No credits recorded in the NVD database.
References
More from NVIDIA
View All →CVE-2025-33255
NVIDIA TRT-LLM for any platform contains a vulnerability in MPI...
High
7.5
CVE-2025-33254
NVIDIA Triton Inference Server contains a vulnerability where an attacker...
High
7.5
CVE-2025-33253
NVIDIA NeMo Framework contains a vulnerability where an attacker could...
High
7.8
CVE-2025-33252
NVIDIA NeMo Framework contains a vulnerability where an attacker could...
High
7.8
CVE-2025-33251
NVIDIA NeMo Framework contains a vulnerability where an attacker could...
High
7.8
Affected Vendor
NVIDIA
View all reports →Affected Software
BlueField GA, BlueField LTS22, BlueField LTS23, BlueField LTS24, ConnectX GA, ConnectX LTS22, ConnectX LTS23, ConnectX LTS24, ConnectX-4, ConnectX-4 LX
Vulnerable Versions:
All versions prior to 46.3008, All versions prior to 35.8002, All versions prior to 39.8002, All versions prior to 43.8002, All versions prior to 28.4702, All versions prior to 32.1908
Timeline
Official Publish:
July 1st, 2026
Last Modified:
July 1st, 2026
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H