Executive brief
NVIDIA Infrastructure Controller for Linux uses a hard-coded password that an attacker could exploit to gain unauthorized access. Successful exploitation could allow tampering with system data, disrupting service availability, or stealing sensitive information from managed infrastructure.
Technical details
The vulnerability involves use of a hard-coded password in NVIDIA Infrastructure Controller for Linux, allowing authentication bypass without legitimate credentials. An attacker with network access can exploit this to gain control of the controller, enabling data tampering, denial of service, and information disclosure. A patch is expected from NVIDIA.
Affected products
- NVIDIA Infrastructure Controller for Linux
Timeline
- 2026-09-22: disclosed