Executive brief
NVIDIA NVOS is the operating system for network switches that manage data center traffic and connectivity. This vulnerability in the SSH (remote administrative access) component creates an alternative login path when a security feature called PKA-only mode is enabled. If administrators do not change the default password as instructed, attackers could gain unauthorized remote access and take full control of the network switch.
Technical details
This vulnerability exists in the SSH server configuration component of NVIDIA NVOS when PKA-only mode is enabled. The flaw allows an alternative authentication path to be inadvertently enabled, which, if combined with failure to replace the default password per NVIDIA's recommendations, provides unauthorized access. The attack vector is network-based and requires no user interaction. A successful exploit enables privilege escalation on the affected network switch. Patches are expected to be available through NVIDIA's security advisory process.
Affected products
- NVIDIA NVOS unspecified
Timeline
- 2026-08-18: disclosed