CVE-2025-33207
MEDIUMDescription
NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register interface by sending a malicious command to the firmware. A successful exploit of this vulnerability might lead to denial of service.
Is your site exposed to CVE-2025-33207?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2025-33207? +
How severe is CVE-2025-33207? +
How do I check if I'm vulnerable to CVE-2025-33207? +
Related Vulnerabilities
Improper access control for register interface in the input-output memory management unit (IOMMU) could allow a privileged attacker to cause …
Improper register access control in ASP may allow a privileged attacker to perform unauthorized access to ASP’s Crypto Co-Processor (CCP) …
Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user …
Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR.
An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the …
A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been rated as critical. Affected by …