CVE-2025-33181
7.3NVIDIA · Cumulus Linux and NVOS
NVIDIA Cumulus Linux and NVOS contain a command injection vulnerability in the NVUE interface that allows a low-privileged user to escalate privileges.
Executive summary
A command injection vulnerability in the NVIDIA NVUE interface allows low-privileged authenticated users to escalate privileges and potentially achieve full system control.
Vulnerability
This is a command injection flaw (CWE-77) occurring within the NVUE interface. An authenticated user with low privileges can inject arbitrary commands, resulting in unauthorized privilege escalation.
Business impact
The vulnerability carries a CVSS score of 7.3, indicating high severity due to the potential for total loss of confidentiality, integrity, and availability. Successful exploitation allows an attacker to bypass security controls, potentially leading to unauthorized administrative access, data theft, or complete system compromise of network infrastructure appliances.
Remediation
Immediate Action: Upgrade all affected NVIDIA Cumulus Linux and NVOS instances to the patched versions specified in the NVIDIA security bulletin (a_id/5722).
Proactive Monitoring: Review system logs for anomalous command execution patterns within the NVUE interface and monitor for unauthorized privilege changes.
Compensating Controls: Restrict access to the NVUE management interface to trusted administrative users only and utilize network segmentation to limit exposure of the management plane.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for privilege escalation and the critical role of network operating systems in enterprise security, administrators should prioritize applying the vendor-supplied patches. Ensure that internal access controls to management interfaces are strictly enforced to minimize the surface area for potential exploitation.