Database/Firmware, BMC & network fabric
NVIDIA UFM Enterprise: code injection via the plugin management API from a low-privileged account
Impact
A crafted request to UFM Enterprise's plugin management API lets an authenticated low-privilege user inject code, which NVIDIA says may lead to code execution, privilege escalation and information disclosure. UFM is the management brain for an InfiniBand fabric: an attacker who gets execution there is inside the system that enumerates, configures and monitors the interconnect every training job depends on, and that holds fabric-wide topology and credentials. A read-only or operator-tier UFM account - the kind handed out for monitoring - is enough to cross into full control of the host. All four supported branches are listed as affected: GA and LTS 2023, 2024 and 2025.
Who can reach it
An authenticated user with low privileges on UFM Enterprise, reaching the plugin management API from the adjacent network (CVSS AV:A, PR:L). In practice, anyone with a UFM login on the management VLAN.
What to do
Upgrade UFM Enterprise to the fixed build for your branch (GA, LTS 2025, LTS 2024 or LTS 2023) as listed in NVIDIA bulletin 5809 - the NVD record does not carry the version numbers, so read the bulletin for your branch rather than assuming. The upgrade restarts the UFM services; if this UFM instance also runs the subnet manager, schedule it alongside an SM failover to the standby so the fabric is not left unmanaged. Until patched, audit who holds low-privilege UFM accounts and keep the UFM API off any network reachable by tenants.
References
Related entries
- librdmacm 1.0.16 (userspace RDMA connection-manager library) - default fallback to ibacm port 6125: RDMACVE-2012-4516 · librdmacm 1.0.16 (userspace RDMA connection-manager library) - default fallback to ibacm port 6125High
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxCVE-2023-45745 · Intel TDX moduleHigh
- Dell PowerEdge Server BIOS / Precision Rack BIOS (improper privilege management): An unauthenticated local attackerCVE-2024-0172 · Dell PowerEdge Server BIOS / Precision Rack BIOS (improper privilege management)High
- AMD SEV-SNP firmware (EPYC Milan, Genoa, Bergamo, Siena): SNP firmware fails to restrict where a hypervisor-drivenCVE-2024-21980 · AMD SEV-SNP firmware (EPYC Milan, Genoa, Bergamo, Siena)High
- Intel reference platforms (Seamless Firmware Updates): A race condition in the seamless firmware update mechanism letsCVE-2024-23599 · Intel reference platforms (Seamless Firmware Updates)High
- Dell SmartFabric OS10 (hard-coded password): A hard-coded password in SmartFabric OS10 10.5.5.4-10.5.5.10 and 10.5.6.xCVE-2024-39585 · Dell SmartFabric OS10 (hard-coded password)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.