CVE-2025-33207: NVIDIA Bluefield Ga
Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.
NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register interface by sending a malicious command to the firmware. A successful exploit of this vulnerability might lead to denial of service.
Affected products
- NVIDIA Bluefield Ga: before 47.1020 (fixed in 47.1020)
- NVIDIA Bluefield LTS23: before 39.5124 (fixed in 39.5124)
- NVIDIA Bluefield LTS24: before 43.4100 (fixed in 43.4100)
- NVIDIA Connectx-5: before 16.35.8008 (fixed in 16.35.8008)
- NVIDIA Connectx Ga: before 47.1020 (fixed in 47.1020)
- NVIDIA Connectx LTS23: before 39.5124 (fixed in 39.5124)
- NVIDIA Connectx LTS24: before 43.4100 (fixed in 43.4100)
Published 2026-09-29. Last modified 2026-09-29.