CVE-2025-33207EPSS p3.7%

CVE-2025-33207CVE-2025-33207

Description

NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register interface by sending a malicious command to the firmware. A successful exploit of this vulnerability might lead to denial of service.

Scoring

CVSS 6.8 ()
VectorCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
EPSS0.15% probability of exploitation · percentile 3.7% · 2026-10-05T12:00:23Z
Last modified2026-09-29
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.