CVE-2025-33180
8.0NVIDIA · Cumulus Linux and NVOS
NVIDIA Cumulus Linux and NVOS products contain a command injection vulnerability in the NVUE interface that allows low-privileged users to escalate privileges.
Executive summary
A command injection vulnerability in the NVIDIA NVUE interface allows authenticated low-privileged users to achieve privilege escalation, posing a significant risk to network infrastructure integrity.
Vulnerability
This is a command injection vulnerability (CWE-77) located in the NVUE interface. It permits an authenticated user with low privileges to inject arbitrary commands, resulting in privilege escalation.
Business impact
The vulnerability carries a CVSS score of 8.0, indicating high severity. Successful exploitation allows an attacker to bypass security controls and gain elevated access to network operating systems, which could lead to unauthorized configuration changes, data exfiltration, or complete loss of control over the affected network switches.
Remediation
Immediate Action: Update NVIDIA Cumulus Linux and NVOS to the patched versions specified in the NVIDIA security advisory (a_id/5722) immediately.
Proactive Monitoring: Monitor system logs for unauthorized command execution attempts or unusual activity originating from low-privileged accounts within the NVUE interface.
Compensating Controls: Restrict access to the NVUE interface to trusted administrative networks and implement strict role-based access control to limit the potential impact of compromised low-privileged accounts.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical nature of network infrastructure, administrators must prioritize patching these affected NVIDIA products. Failure to remediate this vulnerability leaves switches exposed to internal threats, potentially allowing a low-privileged user to gain full administrative control over the network environment.