Executive brief
NVIDIA Infrastructure Controller for Linux, a system management component used to monitor and control infrastructure hardware, contains a flaw that allows attackers to bypass certificate validation. An attacker could exploit this to intercept, modify, or disrupt communications, potentially leading to unauthorized access to sensitive system information, tampering with critical infrastructure commands, or service disruption.
Technical details
The vulnerability involves improper X.509 certificate validation in NVIDIA Infrastructure Controller for Linux, allowing network-based attackers to bypass trust verification mechanisms. Exploitation requires network access to the affected component and can result in information disclosure, data modification, and denial of service without requiring authentication or user interaction.
Affected products
- NVIDIA Infrastructure Controller for Linux <UNKNOWN>
Timeline
- 2026-09-22: disclosed