Database/Firmware, BMC & network fabric
NVIDIA UFM Enterprise: crafted user-management API request lets an admin inject commands on the fabric manager
Impact
An authenticated administrator can send a crafted request to the user management component and have commands executed by UFM itself, per NVIDIA's advisory, leading to code execution, privilege escalation and information disclosure. UFM is the control point for an InfiniBand fabric: a host that runs it holds subnet manager authority, fabric topology and credentials for the switches it manages. Code execution there converts an account that was only supposed to administer UFM into control of the host, and from there into a position on the fabric that crosses every tenant sharing it. All supported branches are listed - GA and LTS 2023, 2024 and 2025.
Who can reach it
An authenticated user with administrative privileges on UFM, reaching the API from an adjacent network - in practice the management VLAN the fabric manager sits on. High privilege is required, so this is a privilege-boundary break inside the management plane rather than a remote entry point.
What to do
Update UFM Enterprise to the fixed build for your branch as listed in NVIDIA's advisory (GA, LTS 2023, LTS 2024, LTS 2025 are all affected); the record given here does not state the fixed version numbers, so read the advisory before scheduling. The upgrade restarts the UFM service, which briefly interrupts fabric management and monitoring but does not require touching compute nodes. Meanwhile, restrict who holds UFM administrator accounts and keep the UFM API off any network a tenant can reach.
References
Related entries
- NVIDIA UFM Enterprise: IBDiagnet API accepts crafted requests that inject commands on the fabric manager hostCVE-2026-24168 · NVIDIA UFM Enterprise (IBDiagnet API)Medium
- OpenBMC bmcweb mTLS client-certificate UPN validation: Where mTLS is configured, bmcweb matches the certificate's UPNNCVD-2026-004-openbmc-bmcweb-mtls-client-certi · OpenBMC bmcweb mTLS client-certificate UPN validationMedium
- Cisco NX-OS CLI: CLI command injection giving root-level execution on the switch OS for an authenticated adminCVE-2017-12334 · Cisco NX-OS CLIMedium
- Intel Server Board / Server System / Compute Module platform firmware: Improper memory initialisation in platformCVE-2018-12204 · Intel Server Board / Server System / Compute Module platform firmwareMedium
- Intel Xeon D / Xeon Scalable system firmware, Server Board and Server System: A buffer overflow in system firmwareCVE-2019-0119 · Intel Xeon D / Xeon Scalable system firmware, Server Board and Server SystemMedium
- Intel SGX / dynamic voltage and frequency scaling interface: Undervolting the CPU through the privilegedCVE-2019-11157 · Intel SGX / dynamic voltage and frequency scaling interfaceMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.