AI analysis
NVIDIA Infrastructure Controller for Linux contains an OS command injection flaw (CWE-78) that allows an attacker to execute arbitrary operating-system commands on the host running the controller. The CVSS 3.1 vector (AV:N/AC:H/PR:H/S:C) indicates the flaw is reachable over the network but requires the attacker to already hold highly privileged access to the controller and to satisfy non-trivial conditions, which limits opportunistic, unauthenticated abuse. A successful exploit could result in code execution, data tampering, denial of service, and information disclosure, with the scope-change metric implying impact extends beyond the controller software itself to the underlying OS. Organizations using the Infrastructure Controller to manage NVIDIA-based Linux GPU/AI infrastructure are the affected population; specific vulnerable version ranges were not enumerated in the available advisory data. There is no known public proof of concept, the CVE is not on CISA's KEV list, and no exploitation in the wild has been reported.
What to do: Apply the patched release NVIDIA identifies in its PSIRT advisory once version details are confirmed, as the affected version range was not included in this data. Until patched, restrict network access to the controller's management interface and minimize the number of highly privileged accounts, since exploitation requires high privileges. Monitor the controller host for unexpected command or process execution originating from the controller service.
Affected
| NVIDIA Infrastructure Controller for Linux | — |
Estimated exposure
moderatelikely on the order of a few thousand enterprise cluster installations — Estimated from deployment pattern — this is data-center infrastructure management software installed per NVIDIA GPU/AI cluster in enterprises rather than a mass-market product, and no public install counts or internet-exposure scan data…
Description
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.