Executive brief
NVIDIA Infrastructure Controller for Linux, used to manage data center infrastructure remotely, contains an XML injection vulnerability that could allow an attacker to tamper with system data or cause service disruptions. A successful attack could compromise infrastructure availability and data integrity without requiring authentication or user interaction.
Technical details
The vulnerability is an XML injection flaw in NVIDIA Infrastructure Controller for Linux that allows attackers to inject malicious XML content. The attack requires network access to the affected service and could lead to data tampering, denial of service, and potentially information disclosure depending on the XML parser implementation and application logic.
Affected products
- NVIDIA Infrastructure Controller for Linux <UNKNOWN>
Timeline
- 2026-09-22: disclosed