CVE-2025-33179

NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could run an unauthorized command. A successful exploit of this vulnerability might lead to escalation of privileges.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:nvidia:cumulus_linux:*:*:*:*:-:*:*:*
cpe:2.3:o:nvidia:cumulus_linux:*:*:*:*:lts:*:*:*
cpe:2.3:o:nvidia:cumulus_linux:*:*:*:*:lts:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:nvidia:nvos:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:dgx_gb200:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:nvidia:nvos:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:gb300_nvl72:1.0:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:nvidia:nvos:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:quantum-x800:-:*:*:*:*:*:*:*

History

27 Feb 2026, 20:03

Type Values Removed Values Added
CPE cpe:2.3:o:nvidia:nvos:*:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:cumulus_linux:*:*:*:*:lts:*:*:*
cpe:2.3:h:nvidia:gb300_nvl72:1.0:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:quantum-x800:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:dgx_gb200:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:cumulus_linux:*:*:*:*:-:*:*:*
References () https://nvd.nist.gov/vuln/detail/CVE-2025-33179 - () https://nvd.nist.gov/vuln/detail/CVE-2025-33179 - Third Party Advisory, US Government Resource
References () https://nvidia.custhelp.com/app/answers/detail/a_id/5722 - () https://nvidia.custhelp.com/app/answers/detail/a_id/5722 - Vendor Advisory
References () https://www.cve.org/CVERecord?id=CVE-2025-33179 - () https://www.cve.org/CVERecord?id=CVE-2025-33179 - Third Party Advisory
CWE NVD-CWE-noinfo
First Time Nvidia cumulus Linux
Nvidia
Nvidia nvos
Nvidia gb300 Nvl72
Nvidia dgx Gb200
Nvidia quantum-x800

24 Feb 2026, 20:27

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-24 20:27

Updated : 2026-02-27 20:03


NVD link : CVE-2025-33179

Mitre link : CVE-2025-33179

CVE.ORG link : CVE-2025-33179


JSON object : View

Products Affected

nvidia

  • cumulus_linux
  • dgx_gb200
  • nvos
  • gb300_nvl72
  • quantum-x800
CWE
CWE-266

Incorrect Privilege Assignment

NVD-CWE-noinfo