Database/Firmware, BMC & network fabric
NVIDIA UFM Enterprise: hard-coded key in session management allows information disclosure and privilege escalation
Impact
UFM is the management plane for the InfiniBand fabric that carries every tenant's collective traffic, so anything that raises privilege on the UFM host reaches across tenant boundaries. NVIDIA states that an attacker can use a hard-coded cryptographic key in the session management component to extract information, and that a successful exploit might lead to information disclosure and escalation of privileges. A hard-coded key is identical on every deployment, so recovering it once from any copy of the product is enough; the record does not describe which session material is protected by it or how far the resulting privilege reaches. CVSS is scored local-vector with high attack complexity and no privileges required (5.1).
Who can reach it
Local access to the UFM Enterprise host or appliance. The CVSS vector is AV:L/AC:H/PR:N/UI:N, so no authentication to UFM itself is required, but the attacker must already be able to run in that context.
What to do
Apply the fixed UFM Enterprise build from NVIDIA advisory 5809; the record lists GA and the LTS 2023, LTS 2024 and LTS 2025 branches as affected but does not name fixed version numbers, so read the advisory for the version matching your branch. Upgrading UFM restarts the fabric-management service - if UFM is also running the subnet manager, plan the window around SM failover rather than doing it under load. Fabric hosts do not need to be drained.
References
Related entries
- IBM PowerVM PKS and virtual TPM: persistent key seeds produce a reduced-strength AES keyCVE-2026-4936 · IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM, FW950 / FW1060 / FW1110Medium
- OpenIPMI before 2.0.36: Where this bites an operator is in test and CI infrastructure rather than production nodesCVE-2024-42934 · OpenIPMI before 2.0.36Medium
- Eaton UPS 9PX 8000 SP web interface: The device's own web page contains the user password in cleartext in the pageCVE-2018-9279 · Eaton UPS 9PX 8000 SP web interfaceMedium
- NVIDIA DGX BMC (AMI firmware): An administrative BMC user can pull the hash of the BMC/IPMI user passwordCVE-2020-11484 · NVIDIA DGX BMC (AMI firmware)Medium
- AMI MegaRAC SPx 12 / SPx 13 (BMC TLS certificate generation): Malformed input to the BMC's certificate-generationCVE-2021-44769 · AMI MegaRAC SPx 12 / SPx 13 (BMC TLS certificate generation)Medium
- IBM OpenBMC OP910 / OP940 certificate handling (phosphor-certificate-manager lineage): A privileged BMC userCVE-2022-22488 · IBM OpenBMC OP910 / OP940 certificate handling (phosphor-certificate-manager lineage)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.