CVE-2026-65130: OS Command Injection
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation is network-accessible but requires high privileges. No user interaction is required.
What impacts could successful exploitation have?
Successful exploitation may allow code execution, data tampering, denial of service, and information disclosure. The CVSS vector rates confidentiality, integrity, and availability impacts as high, with scope changed.
Is exploitation expected to be straightforward?
No. The CVSS vector identifies attack complexity as high, indicating that exploitation requires conditions beyond simply reaching a vulnerable network-exposed interface.