Impact
A flaw in NVIDIA AIStore framework permits an attacker to bypass authentication controls, enabling actions without valid credentials. The resulting impact can include denial of service, privilege escalation, information disclosure, and data tampering. The weakness is identified as authorization failure (CWE-290).
Affected Systems
The NVIDIA AIStore framework is the affected product. No specific affected versions are listed in the CVE data, so all installations of this framework are potentially vulnerable unless a later release has mitigated the issue.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating critical severity. Its EPSS score is less than 1 %, indicating a very low but non‑zero exploitation probability, and it is not included in the CISA KEV catalog. The likely attack vector is remote exploitation through the AIStore interface, inferred because the flaw allows actions without authentication, but this inference is made in the absence of explicit vector data in the CVE description.
OpenCVE Enrichment