AI analysis
NVIDIA Infrastructure Controller for Linux, a management component used on NVIDIA GPU server infrastructure, contains an improper authentication flaw (CWE-287) rated high severity at CVSS 8.2. The CVSS vector (AV:A/PR:N/UI:N) indicates an attacker on the same network segment as the controller, holding no credentials and requiring no user interaction, can submit requests that are not correctly authenticated; because the scope changes (S:C), the impact reaches beyond the component itself. A successful exploit can yield escalation of privileges, high-impact information disclosure, and data tampering on the affected host. Organizations running this controller on Linux GPU infrastructure (typically DGX/HGX-class servers in data centers) are affected, though exact affected versions were not specified in the available data. There is no known public proof of concept, the CVE is not on the CISA KEV list, and no exploitation in the wild has been reported.
What to do: Check the NVIDIA PSIRT advisory for the affected version list and upgrade to the patched release as soon as it is available. Until then, restrict the controller's management interface to trusted admin networks via VLAN segmentation or host-firewall allowlists, since exploitation requires adjacent-network access with no credentials. Run the controller with least privilege and monitor GPU nodes for unauthenticated requests or unexpected privileged activity.
Affected
| NVIDIA Infrastructure Controller for Linux | — |
Estimated exposure
large≈ tens of thousands of GPU servers (rough order-of-magnitude estimate only) — The component ships with NVIDIA's data-center GPU server manageability stack on DGX/HGX-class systems, of which several hundred thousand are deployed enterprise-wide, but adoption of this specific controller is not publicly counted, so the…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, and data tampering.