CVE-2025-33186

8.8

NVIDIA · AIStore

NVIDIA AIStore is susceptible to a privilege escalation and data tampering vulnerability due to the use of hard-coded credentials within its AuthN component.

Executive summary

A critical vulnerability in the NVIDIA AIStore AuthN component allows unauthenticated attackers to escalate privileges and manipulate sensitive data via hard-coded credentials.

Vulnerability

This flaw stems from the use of hard-coded credentials (CWE-798) within the authentication module of the application. This oversight allows an unauthenticated remote attacker to bypass standard security controls, leading to full unauthorized access to the affected system.

Business impact

The presence of hard-coded credentials represents a severe security failure that can lead to complete system compromise. Successful exploitation enables unauthorized actors to access, modify, or delete sensitive data, potentially resulting in significant data breaches, loss of intellectual property, and severe operational downtime. Given the CVSS score of 8.8, this vulnerability is classified as High severity and requires immediate attention to prevent unauthorized administrative control.

Remediation

Immediate Action: Upgrade all instances of NVIDIA AIStore to version 3.31 or later, which contains the necessary security patches to remove the hard-coded credentials.

Proactive Monitoring: Review system access logs for unusual administrative activity or repeated authentication attempts originating from unexpected IP addresses.

Compensating Controls: Ensure that AIStore instances are isolated from the public internet using firewalls or VPNs to restrict access only to authorized personnel while the patching process is completed.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for full privilege escalation and data manipulation, organizations running NVIDIA AIStore must prioritize the transition to version 3.31 immediately. Apply the vendor-supplied updates as soon as possible to neutralize the risk posed by these hard-coded credentials. Failure to remediate this vulnerability leaves the environment exposed to unauthorized access and potential data exfiltration.

More NVIDIA CVEs

Sources