Dismissed
Permalink
CVE-2025-33181
7.3 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse ignored package convos
- @LeSuisse dismissed
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in …
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit of this vulnerability might lead to escalation of privileges.
References
Affected products
NVOS
- ==All versions prior to 1.3 - 25.02.244
- ==All versions prior to 25.02.5030
- ==All versions prior to 25.02.4282
Cumulus Linux GA
- ==All versions prior to 5.14 (5.13.x, 5.12.x, and older GA versions)
Cumulus Linux LTS
- ==All versions prior to 5.9.4
- ==All versions prior to 5.11.4