{"id":"CVE-2026-65113","published":"2026-09-22T15:17:11.513","lastModified":"2026-09-22T19:37:36.747","description":"NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and information disclosure.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-798"],"vendors":[],"products":[],"references":[{"url":"https://github.com/NVIDIA/product-security/tree/main/2026/5879","tags":[]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65113","tags":[]},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-65113","tags":[]}],"exploitRefs":[{"url":"https://github.com/NVIDIA/product-security/tree/main/2026/5879","tags":[]}],"hasPoc":true,"ai":{"summary":"This vulnerability in NVIDIA Infrastructure Controller for Linux allows attackers to exploit hard-coded credentials, leading to potential privilege escalation, data tampering, denial of service, and information disclosure.","exploitability":"Exploitation is relatively straightforward given the hard-coded credentials, requiring an attacker to have network access to the affected system.","blast_radius":"If exploited, the impact could be severe, affecting the entire system's security and potentially leading to data breaches or service disruptions.","remediation":"Upgrade to the specific version 5.2.3 or later as published by NVIDIA.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","priv-escalation","data-tampering","denial-of-service","info-disclosure"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:49:28.681Z"}}