Impact
The issue lies within the user management component of NVIDIA Cumulus Linux, where unprivileged users can exploit improper privilege management to gain higher privileges. This can lead to unauthorized control, allowing attackers to modify system configuration, compromise data integrity, and potentially disrupt network operations. The weakness is categorized as CWE-250, Privilege Escalation Through Improper Access Control.
Affected Systems
NVIDIA Cumulus Linux General Availability releases are affected. The vulnerability applies to all GA versions of the distribution as identified by NVIDIA.
Risk and Exploitability
The CVSS score of 7.8 reflects high severity, but the EPSS score is not available, suggesting limited public exploitation data. The vulnerability is not listed in the CISA KEV catalog. As the flaw involves user management, the attack likely requires local or network access to the device, possibly via console or management interface, and does not provide remote code execution on its own.
OpenCVE Enrichment