NVIDIA Infrastructure Controller Hit by 14 Flaws Enabling Code Execution and Privilege Escalation
NVIDIA patches 14 vulnerabilities in its Infrastructure Controller, including a critical CVSS 9.8 hard-coded credentials flaw enabling unauthenticated remote privilege escalation.
NVIDIA released version 2.0 of its Infrastructure Controller to patch 14 vulnerabilities in its Linux-based management software. The most severe flaw, CVE-2026-65113, is a critical hard-coded credentials vulnerability with a CVSS score of 9.8 that allows unauthenticated remote attackers to escalate privileges, modify data, and disrupt services. The update also addresses high-severity issues like SQL injection (CVE-2026-65128) and missing authentication (CVE-2026-65114), among others affecting versions 0 through 1.9.