GPU VulnDB

Database/Firmware, BMC & network fabric

NVIDIA UFM Enterprise: hard-coded key in session management allows information disclosure and privilege escalation

CVE-2026-24166Firmware, BMC & network fabriccurated

Impact

UFM is the management plane for the InfiniBand fabric that carries every tenant's collective traffic, so anything that raises privilege on the UFM host reaches across tenant boundaries. NVIDIA states that an attacker can use a hard-coded cryptographic key in the session management component to extract information, and that a successful exploit might lead to information disclosure and escalation of privileges. A hard-coded key is identical on every deployment, so recovering it once from any copy of the product is enough; the record does not describe which session material is protected by it or how far the resulting privilege reaches. CVSS is scored local-vector with high attack complexity and no privileges required (5.1).

Who can reach it

Local access to the UFM Enterprise host or appliance. The CVSS vector is AV:L/AC:H/PR:N/UI:N, so no authentication to UFM itself is required, but the attacker must already be able to run in that context.

What to do

Apply the fixed UFM Enterprise build from NVIDIA advisory 5809; the record lists GA and the LTS 2023, LTS 2024 and LTS 2025 branches as affected but does not name fixed version numbers, so read the advisory for the version matching your branch. Upgrading UFM restarts the fabric-management service - if UFM is also running the subnet manager, plan the window around SM failover rather than doing it under load. Fabric hosts do not need to be drained.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.