Impact
NVIDIA DCGM Exporter for all platforms has a flaw in the /debug/pprof endpoints that permits an attacker to send concurrent, unauthenticated profiling requests, causing uncontrolled resource consumption that can result in a denial‑of‑service condition and potentially expose profiling data. The vulnerability is a classic uncontrolled resource consumption flaw (CWE‑770) targeting the profiling subsystem.
Affected Systems
All NVIDIA DCGM and DCGM Exporter deployments across supported platforms are affected. No specific version range is listed in the advisory, so any installation that contains the /debug/pprof endpoints is potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.2 indicates a high‑severity impact, while the EPSS score of less than 1% suggests a low probability of current exploitation. The vulnerability is not listed in CISA’s KEV catalog. Because the attack vector involves unauthenticated HTTP profiling requests, it is inferred that the exploit can be performed remotely over the network. Successful exploitation would consume system resources, shutting down services and, if not mitigated, can reveal profiling data to the attacker.
OpenCVE Enrichment