GPU VulnDB

Database/Firmware, BMC & network fabric

NVIDIA UFM Enterprise: IBDiagnet API accepts crafted requests that inject commands on the fabric manager host

CVE-2026-24168Firmware, BMC & network fabriccurated

Impact

The IBDiagnet API in UFM Enterprise passes crafted request content into command execution, giving an authenticated administrator code execution, privilege escalation and information disclosure on the fabric manager. IBDiagnet is the fabric diagnostic path, so it is reachable through normal operational tooling rather than an obscure corner of the product. A compromised UFM host means whoever holds it can read fabric topology and credentials and influence the InfiniBand subnet that every tenant on the cluster shares. This is a second injection in the same advisory as CVE-2026-24167 and affects the same GA and LTS 2023/2024/2025 branches.

Who can reach it

An authenticated attacker with administrative privileges on UFM, calling the IBDiagnet API from an adjacent network - normally the management VLAN. No unauthenticated path is described.

What to do

Apply the same UFM Enterprise update that covers CVE-2026-24167, following NVIDIA's advisory for the fixed build on your branch; the record here does not name version numbers. Expect a UFM service restart and a short gap in fabric management and diagnostics; compute nodes are unaffected. Until patched, limit UFM administrator accounts and keep the management interface segmented from tenant networks.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.