CVE-2026-65113
9.8NVIDIA · Infrastructure Controller
NVIDIA Infrastructure Controller for Linux contains a vulnerability involving the use of hard-coded credentials, allowing unauthenticated attackers to gain full system control.
Executive summary
A critical vulnerability in the NVIDIA Infrastructure Controller allows unauthenticated attackers to exploit hard-coded credentials, leading to full system compromise and data tampering.
Vulnerability
The software utilizes hard-coded credentials, which allows an unauthenticated, remote attacker to bypass standard authentication mechanisms. This flaw (CWE-798) enables unauthorized access with elevated privileges, effectively granting control over the affected Linux infrastructure.
Business impact
The exploitation of this vulnerability carries a severe risk to business operations, as it allows for unauthorized data access, system-wide modification, and denial of service. Given the CVSS score of 9.8, this flaw represents a critical threat to the confidentiality, integrity, and availability of any environment running the affected controller.
Remediation
Immediate Action: Monitor official NVIDIA security bulletins for the release of a patched firmware or software version and apply it immediately upon availability.
Proactive Monitoring: Review system authentication logs for anomalous login activity or unexpected administrative access patterns that may indicate a credential-based compromise.
Compensating Controls: Implement strict network segmentation to isolate the Infrastructure Controller from public-facing networks, ensuring that access is restricted to authorized management subnets.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability is classified as critical due to its potential for unauthenticated, remote exploitation. Organizations should prioritize the identification of all instances of the NVIDIA Infrastructure Controller within their environment and prepare for an urgent update cycle as soon as the vendor releases the necessary security patch.
More NVIDIA CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section