Critical NVIDIA Networking Vulnerabilities Highlight the Need for Infrastructure Resilience
Dell has released a critical security advisory (DSA-2026-323) addressing two high-severity vulnerabilities (CVE-2025-23350 and CVE-2025-23351) affecting NVIDIA BlueField and ConnectX networking adapters used in Dell PowerEdge servers. With a CVSS score of 9.0, the vulnerabilities allow an attacker with access to an assigned Virtual Function (VF) in an SR-IOV-enabled environment to execute arbitrary code, cause denial of service, or potentially compromise the underlying host.
For organisations operating virtualised infrastructure, the risk extends well beyond a single server. A successful attack against the underlying host could allow an attacker to compromise multiple virtual machines, access sensitive business systems, and move laterally across the environment. For organisations hosting multi-tenant workloads, this creates the potential for a single compromised workload to impact every application and customer sharing that infrastructure.
While Dell has released firmware and driver updates to address the issue, this advisory serves as a timely reminder that infrastructure vulnerabilities are becoming increasingly attractive targets for attackers. Effective cyber resilience requires more than timely patching - it also depends on understanding infrastructure dependencies, maintaining deep visibility across the network, and limiting an attacker's ability to move laterally should a compromise occur.
Applying Dell's security updates should be the immediate priority. However, vulnerabilities affecting critical infrastructure will continue to emerge.
The real question organisations should ask is:
If one server is compromised tomorrow, how quickly can we identify it, understand its impact, and stop an attacker moving any further?
A resilient cybersecurity strategy requires more than effective patch management.
1. Know What Is Affected
When a critical vulnerability is announced, organisations need immediate answers:
- Which business services rely on the affected servers?
- Which applications communicate with them?
- What systems will be impacted by emergency maintenance?
- Where are the highest business risks?
Without accurate infrastructure and application dependency information, vulnerability response becomes slower, more disruptive and far more difficult to prioritise.
Strong network governance and application dependency mapping enable security and operations teams to make informed decisions during critical security events.
2. Improve Visibility Across Your Infrastructure
Infrastructure-focused attacks are becoming increasingly sophisticated.
Traditional security tools often focus on endpoints, leaving reduced visibility into:
- East-west traffic
- Virtualised environments
- Hybrid cloud infrastructure
- High-speed network communications
- Encrypted traffic flows
Comprehensive network visibility enables security teams to identify unusual communication patterns, investigate suspicious activity and validate that segmentation controls are working as intended.
The better you can see your environment, the faster you can detect abnormal behaviour before it develops into a major incident.
3. Contain the Blast Radius
The biggest risk posed by these vulnerabilities isn't necessarily the initial compromise - it's what happens next.
If an attacker can move freely between workloads, management systems and business-critical applications, a single compromised virtual machine can quickly become an enterprise-wide incident.
Zero Trust Segmentation helps contain that risk by enforcing least-privilege communication between applications and systems.
Even if a host is compromised, segmentation policies can prevent attackers from moving laterally, protecting critical applications and significantly reducing the potential impact of an attack.
For organisations operating shared infrastructure, critical services or regulated environments, segmentation has become an essential security control.
Security Is About Resilience
Critical vulnerabilities like CVE-2025-23350 and CVE-2025-23351 reinforce an important lesson:
No organisation can prevent every vulnerability - but every organisation can reduce its impact.
The organisations best prepared for future infrastructure threats are those that can:
- Understand their infrastructure and application dependencies.
- Observe network activity across physical, virtual and cloud environments.
- Contain attackers before they can move laterally.
Combining timely patch management with network governance, deep infrastructure visibility and Zero Trust Segmentation creates a far more resilient security posture - one that limits business disruption even when new vulnerabilities inevitably emerge.
