Database/Firmware, BMC & network fabric
NVIDIA UFM Enterprise: IBDiagnet API accepts crafted requests that inject commands on the fabric manager host
Impact
The IBDiagnet API in UFM Enterprise passes crafted request content into command execution, giving an authenticated administrator code execution, privilege escalation and information disclosure on the fabric manager. IBDiagnet is the fabric diagnostic path, so it is reachable through normal operational tooling rather than an obscure corner of the product. A compromised UFM host means whoever holds it can read fabric topology and credentials and influence the InfiniBand subnet that every tenant on the cluster shares. This is a second injection in the same advisory as CVE-2026-24167 and affects the same GA and LTS 2023/2024/2025 branches.
Who can reach it
An authenticated attacker with administrative privileges on UFM, calling the IBDiagnet API from an adjacent network - normally the management VLAN. No unauthenticated path is described.
What to do
Apply the same UFM Enterprise update that covers CVE-2026-24167, following NVIDIA's advisory for the fixed build on your branch; the record here does not name version numbers. Expect a UFM service restart and a short gap in fabric management and diagnostics; compute nodes are unaffected. Until patched, limit UFM administrator accounts and keep the management interface segmented from tenant networks.
References
Related entries
- OpenBMC bmcweb mTLS client-certificate UPN validation: Where mTLS is configured, bmcweb matches the certificate's UPNNCVD-2026-004-openbmc-bmcweb-mtls-client-certi · OpenBMC bmcweb mTLS client-certificate UPN validationMedium
- Cisco NX-OS CLI: CLI command injection giving root-level execution on the switch OS for an authenticated adminCVE-2017-12334 · Cisco NX-OS CLIMedium
- Intel Server Board / Server System / Compute Module platform firmware: Improper memory initialisation in platformCVE-2018-12204 · Intel Server Board / Server System / Compute Module platform firmwareMedium
- Intel Xeon D / Xeon Scalable system firmware, Server Board and Server System: A buffer overflow in system firmwareCVE-2019-0119 · Intel Xeon D / Xeon Scalable system firmware, Server Board and Server SystemMedium
- Intel SGX / dynamic voltage and frequency scaling interface: Undervolting the CPU through the privilegedCVE-2019-11157 · Intel SGX / dynamic voltage and frequency scaling interfaceMedium
- NVIDIA DGX BMC (AMI firmware): The BMC does not validate the RSA-1024 public key used to verify firmware signaturesCVE-2020-11488 · NVIDIA DGX BMC (AMI firmware)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.