CVE-2026-65114

8.3

NVIDIA · Infrastructure Controller

NVIDIA Infrastructure Controller for Linux contains a vulnerability involving missing authentication for a critical function that allows unauthenticated access.

Executive summary

A critical vulnerability in the NVIDIA Infrastructure Controller for Linux allows unauthenticated attackers to perform data tampering, denial of service, and information disclosure.

Vulnerability

This flaw is identified as CWE-306, where a critical function in the Infrastructure Controller lacks necessary authentication checks. The CVSS vector (AV:A/AC:L/PR:N/UI:N) confirms that the vulnerability is exploitable by an unauthenticated attacker located on the adjacent network.

Business impact

The ability for an unauthenticated attacker to manipulate data or disrupt services poses a significant risk to operational integrity. With a CVSS score of 8.3, this high-severity vulnerability could lead to unauthorized system modification and potential service outages, necessitating immediate attention to prevent data compromise.

Remediation

Immediate Action: Review the official NVIDIA security advisory and apply the latest security patches provided by the vendor to address this missing authentication flaw.

Proactive Monitoring: Monitor network traffic and system access logs for unauthorized attempts to access management endpoints or unusual traffic patterns originating from the adjacent network.

Compensating Controls: Implement strict network segmentation to restrict access to the Infrastructure Controller, ensuring only authorized devices can communicate with the management interface.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the potential for unauthorized data tampering, organizations using NVIDIA Infrastructure Controller versions 0 through 1.9 must prioritize testing and deploying the vendor's security updates. If patching is not immediately feasible, ensure that network-level access controls are robust enough to mitigate the risk of unauthorized adjacent network access.

More NVIDIA CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources