AI analysis
NVIDIA Infrastructure Controller for Linux ships with hard-coded credentials (CWE-798), and the CVSS 9.8 vector indicates it is exploitable over the network with no privileges, no authentication, and no user interaction. An attacker who can reach the affected service could use the embedded credentials to authenticate as a trusted component, potentially escalating privileges, tampering with data, causing denial of service, and disclosing information. The product is enterprise GPU-cluster/AI-infrastructure management software, so the primary blast radius is data-center and AI operations rather than consumer devices. No public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and there is no evidence of in-the-wild exploitation as of this writing. Because successful exploitation yields full impact on confidentiality, integrity, and availability, internet-reachable or broadly network-exposed deployments should be treated as high risk.
What to do: Apply the patched version specified in NVIDIA's security advisory for Infrastructure Controller for Linux as soon as it is available. Until patched, restrict network access to the controller's management interfaces (firewall rules, VPN, or management VLAN) so only trusted administrators and cluster nodes can reach it. Review authentication and audit logs for unexpected logins or privilege changes, and rotate any credentials or tokens that the controller shares with dependent systems.
Affected
| NVIDIA Infrastructure Controller for Linux | — |
Estimated exposure
niche≈ hundreds to low thousands of installations (enterprise GPU/AI cluster management deployments, mostly data-center internal) — This is enterprise-only cluster management software for NVIDIA GPU infrastructure deployed on-premises in data centers rather than a consumer or web-hosted product; no public install counts or internet-exposure scan data are available, so…
Description
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and information disclosure.