UFM Enterprise / UFM Appliance / UFM CyberAI: Fabric-manager privesc, data corruption, service disruption via improper
CVSS 8.8CVE-2024-0130NVIDIA / GPU stackcurated
Impact
Fabric-manager privesc, data corruption, service disruption via improper authentication on the Ethernet mgmt interface
Who can reach it
Network-adjacent attacker on the fabric management network
What to do
Upgrade UFM; isolate the UFM mgmt interface to a dedicated VLAN; no tenant eviction, but InfiniBand fabric control is at stake
References
Related entries
- NVIDIA App: Local privescCVE-2025-23253 · NVIDIA AppHigh
- TensorRT-LLM: RCE via unsafe pickle deserializationCVE-2025-23254 · TensorRT-LLMHigh
- NVIDIA AIStore - AuthN: A flaw in the AIStore authentication component reaches privilege escalation, informationCVE-2025-33186 · NVIDIA AIStore - AuthNHigh
- NVIDIA TAO Toolkit: An uncontrolled search path loads an attacker-planted resource, reaching privilege escalationCVE-2025-33208 · NVIDIA TAO ToolkitHigh
- NVIDIA Merlin Transformers4Rec: The Trainer component deserializes untrusted data, reaching code executionCVE-2025-33213 · NVIDIA Merlin Transformers4RecHigh
- NVIDIA NVTabular: The Workflow component deserializes untrusted data, reaching code executionCVE-2025-33214 · NVIDIA NVTabularHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.