← Back to search

CVE-2026-65113

9.8 CRITICALpublic exploit available

Published 2026-09-22 · Updated 2026-09-22

AI risk analysis

Summary
This vulnerability in NVIDIA Infrastructure Controller for Linux allows attackers to exploit hard-coded credentials, leading to potential privilege escalation, data tampering, denial of service, and information disclosure.
Exploitability
Exploitation is relatively straightforward given the hard-coded credentials, requiring an attacker to have network access to the affected system.
Blast radius
If exploited, the impact could be severe, affecting the entire system's security and potentially leading to data breaches or service disruptions.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the specific version 5.2.3 or later as published by NVIDIA.
rcepriv-escalationdata-tamperingdenial-of-serviceinfo-disclosure

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and information disclosure.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-798

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.