Impact
NVIDIA reports that the example and recipe code provided with its Dynamo package for Linux contains a flaw that can let an attacker trigger a system failure. If exploited, the vulnerability can allow arbitrary code execution, data modification, denial of service, or information disclosure, as summarized in the advisory. The weakness is identified as CWE‑1357, indicating a likely unhandled input or execution path that can lead to a crash or unintended behavior.
Affected Systems
The affected product is NVIDIA Dynamo for Linux. The flaw exists in the example and recipe bundles that ship with the installation. No specific product versions are listed, so all releases that include these bundled examples are potentially vulnerable until a patch is applied or the examples are removed or secured.
Risk and Exploitability
The CVSS score is 6.6, classifying the issue as medium severity. Because no EPSS score is provided, the likelihood of exploitation is uncertain. The vulnerability is not listed in CISA's KEV catalog. Based on the description, the attack vector is inferred to be local execution of malicious or modified example scripts; a remote attacker would need local file execution authority or a pre‑existing code execution capability. Despite the moderate score, the potential for system failure and data compromise requires prompt remediation.
OpenCVE Enrichment