CVE-2026-65114
8.3NVIDIA · Infrastructure Controller
NVIDIA Infrastructure Controller for Linux contains a vulnerability involving missing authentication for a critical function that allows unauthenticated access.
Executive summary
A critical vulnerability in the NVIDIA Infrastructure Controller for Linux allows unauthenticated attackers to perform data tampering, denial of service, and information disclosure.
Vulnerability
This flaw is identified as CWE-306, where a critical function in the Infrastructure Controller lacks necessary authentication checks. The CVSS vector (AV:A/AC:L/PR:N/UI:N) confirms that the vulnerability is exploitable by an unauthenticated attacker located on the adjacent network.
Business impact
The ability for an unauthenticated attacker to manipulate data or disrupt services poses a significant risk to operational integrity. With a CVSS score of 8.3, this high-severity vulnerability could lead to unauthorized system modification and potential service outages, necessitating immediate attention to prevent data compromise.
Remediation
Immediate Action: Review the official NVIDIA security advisory and apply the latest security patches provided by the vendor to address this missing authentication flaw.
Proactive Monitoring: Monitor network traffic and system access logs for unauthorized attempts to access management endpoints or unusual traffic patterns originating from the adjacent network.
Compensating Controls: Implement strict network segmentation to restrict access to the Infrastructure Controller, ensuring only authorized devices can communicate with the management interface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS score and the potential for unauthorized data tampering, organizations using NVIDIA Infrastructure Controller versions 0 through 1.9 must prioritize testing and deploying the vendor's security updates. If patching is not immediately feasible, ensure that network-level access controls are robust enough to mitigate the risk of unauthorized adjacent network access.
More NVIDIA CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section