CVE-2025-33222
9.8NVIDIA · Isaac Launchable
NVIDIA Isaac Launchable is affected by a hard-coded credential vulnerability, allowing unauthenticated remote attackers to gain unauthorized access and execute code.
Executive summary
A critical hard-coded credential vulnerability in NVIDIA Isaac Launchable exposes the system to unauthorized remote access and potential code execution.
Vulnerability
This vulnerability is classified as CWE-798 (Use of Hard-coded Credentials). The CVSS vector confirms the vulnerability is remotely exploitable (AV:N) and requires no authentication (PR:N) or user interaction (UI:N).
Business impact
Hard-coded credentials allow attackers to bypass standard authentication mechanisms, granting them unauthorized access to the application. Given the CVSS score of 9.8, this flaw facilitates severe outcomes, including full system compromise, data theft, and persistent unauthorized access, which could lead to significant reputational and operational damage.
Remediation
Immediate Action: Update NVIDIA Isaac Launchable to version 1.1 or later to remove the hard-coded credentials and implement secure authentication practices.
Proactive Monitoring: Inspect application authentication logs for successful logins using generic or unexpected credentials, which may indicate exploitation attempts.
Compensating Controls: Isolate the affected system from the public internet and restrict access to trusted, hardened management networks to mitigate the risk of credential misuse.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The presence of hard-coded credentials constitutes a critical security failure. Administrators should prioritize the deployment of the 1.1 update immediately to replace the insecure authentication mechanism and secure the application against unauthorized access.