GPU VulnDB

Database/Firmware, BMC & network fabric

NVIDIA UFM Enterprise: web interface authorization flaw leads to code execution on the fabric manager

CVE-2026-24170Firmware, BMC & network fabriccurated

Impact

Crafted HTTP requests to the UFM web interface defeat its authorization checks, which NVIDIA says may lead to code execution and privilege escalation. UFM is the management brain of an InfiniBand fabric: whoever runs code there can read the fabric topology, and the fabric is the one component in a GPU cluster that every tenant's traffic crosses. Compromise of it puts partitioning, routing and telemetry for the whole cluster in the attacker's hands rather than a single node's. All currently listed branches are affected - GA plus LTS 2023, 2024 and 2025 - so long-lived clusters on an LTS line are not exempt. Note the tension in the record: NVIDIA's description says an authenticated user, while the vector it published is scored PR:N, so plan on management-network reach being enough.

Who can reach it

Adjacent network (CVSS AV:A) - anyone who can reach the UFM web interface, which should mean only the management VLAN. NVIDIA's text says an authenticated user; the published vector requires no privileges.

What to do

Take the fixed build for your branch from NVIDIA security bulletin 5809 - the record supplied here does not name version numbers, so read the bulletin for the GA/LTS 2023/2024/2025 fix levels rather than assuming one. Applying it is a UFM software upgrade and service restart on the management host; if that UFM instance is running the active subnet manager, schedule the restart as an SM failover window. In the meantime, confirm the UFM web interface is not reachable from tenant or general corporate networks.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.