Executive brief
NVIDIA Infrastructure Controller for Linux, a system management tool for Linux servers, contains a missing authentication vulnerability in a critical function. An attacker could exploit this to tamper with data, disrupt service availability, or access sensitive system information without authorization.
Technical details
An authentication check is missing from a critical function in NVIDIA Infrastructure Controller for Linux, allowing unauthenticated access via network. The vulnerability permits data tampering, denial of service, and information disclosure. The reported CVSS score is 8.3.
Affected products
- NVIDIA Infrastructure Controller for Linux
Timeline
- 2026-09-22: disclosed