Description
NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could inadvertently enable an alternative authentication path. If best practices for replacing the default password as recommended by NVIDIA are not followed, this alternative authentication path might lead to unauthorized access. A successful exploit of this vulnerability might lead to escalation of privileges.
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NVIDIA NVOS for network switches contains a flaw in the secure shell (SSH) server configuration when PKA-only mode is enabled. The configuration permits an administrator to enable an alternative authentication path if the default password remains unchanged. An attacker who exploits this can obtain unauthorized access and potentially elevate privileges on the device. The flaw represents a failure to enforce the intended authentication method, allowing misuse of a legacy credential path.

Affected Systems

The affected product is NVIDIA NVOS running on network switches. No specific firmware or software versions are listed in the available data, so all current releases of NVOS with SSH enabled under PKA-only mode may be at risk.

Risk and Exploitability

The CVSS score of 7.1 indicates a high‑severity vulnerability. The EPSS score is not provided, so the current exploitation probability cannot be quantified, and the vulnerability is not yet cataloged in the CISA KEV list. Likely exploitation requires remote access to the SSH service and the presence of the default password, an oversight that can be inferred from the description. If the best‑practice step of replacing the default password is not followed, an attacker can leverage the alternative authentication path to gain privileged access to the switch.

Generated by OpenCVE AI on August 18, 2026 at 19:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Configure NVOS to enforce PKA‑only mode strictly and disable any alternate authentication paths in the SSH server configuration.
  • Replace the default NVIDIA password with a strong, unique password or disable password‑based authentication entirely.
  • Upgrade NVOS to the latest firmware release that addresses the SSH configuration flaw, if available.
  • If an upgrade is unavailable, restrict SSH access to trusted IP ranges or apply additional network segmentation to mitigate exposure.

Generated by OpenCVE AI on August 18, 2026 at 19:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Vulnerability in NVOS SSH Server Configuration Allows Unauthorized Access When PKA-Only Mode Enabled

Tue, 18 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia nvos
Vendors & Products Nvidia
Nvidia nvos

Tue, 18 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could inadvertently enable an alternative authentication path. If best practices for replacing the default password as recommended by NVIDIA are not followed, this alternative authentication path might lead to unauthorized access. A successful exploit of this vulnerability might lead to escalation of privileges.
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-08-18T18:40:28.532Z

Reserved: 2026-01-21T19:09:32.732Z

Link: CVE-2026-24185

cve-icon Vulnrichment

Updated: 2026-08-18T18:40:25.425Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T19:16:46.410

Modified: 2026-08-20T13:06:05.500

Link: CVE-2026-24185

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T20:00:04Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel