Impact
This vulnerability is an improper authentication flaw in the NVIDIA Delegated Licensing Service, which is part of NVIDIA's License System for all appliance platforms. The flaw enables an attacker to bypass normal authentication controls and potentially access sensitive data that is protected by the licensing service. The exposed information could include proprietary licensing information or other confidential data stored on the service, leading to confidentiality compromise.
Affected Systems
The affected component is the NVIDIA Delegated Licensing Service running on NVIDIA appliance platforms. Specific product versions are not provided in the CNA data, so all installations of this service on supported appliance platforms are potentially impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score is reported as less than 1%, showing a very low but non-zero probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote; an attacker could exploit the authentication weakness by interacting with the service over the network, possibly via exposed APIs or management interfaces. No additional exploitation conditions are described, and the impact is limited to information disclosure rather than full system compromise.
OpenCVE Enrichment