Executive brief
NVIDIA's Infrastructure Controller for Linux contains hard-coded credentials that an attacker could exploit to gain unauthorized access. A successful attack could allow privilege escalation, unauthorized data access and modification, service disruptions, and exposure of sensitive information.
Technical details
The vulnerability stems from the use of hard-coded credentials in NVIDIA Infrastructure Controller for Linux, allowing unauthenticated or low-privileged attackers to leverage these credentials for privilege escalation and unauthorized system access. The attack vector is network-accessible, enabling remote exploitation. An attacker gains the ability to execute arbitrary actions with elevated privileges, potentially leading to full system compromise.
Affected products
- NVIDIA Infrastructure Controller for Linux
Timeline
- 2026-09-22: disclosed