Impact
NVIDIA NVOS for network switches contains a flaw in the secure shell (SSH) server configuration when PKA-only mode is enabled. The configuration permits an administrator to enable an alternative authentication path if the default password remains unchanged. An attacker who exploits this can obtain unauthorized access and potentially elevate privileges on the device. The flaw represents a failure to enforce the intended authentication method, allowing misuse of a legacy credential path.
Affected Systems
The affected product is NVIDIA NVOS running on network switches. No specific firmware or software versions are listed in the available data, so all current releases of NVOS with SSH enabled under PKA-only mode may be at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity vulnerability. The EPSS score is not provided, so the current exploitation probability cannot be quantified, and the vulnerability is not yet cataloged in the CISA KEV list. Likely exploitation requires remote access to the SSH service and the presence of the default password, an oversight that can be inferred from the description. If the best‑practice step of replacing the default password is not followed, an attacker can leverage the alternative authentication path to gain privileged access to the switch.
OpenCVE Enrichment