Impact
During the NemoClaw installation process the vendor fails to isolate untrusted code, allowing an attacker to execute arbitrary binaries. The vulnerability can culminate in code execution, elevation of privileges, alteration of data, disclosure of sensitive information, and a denial‑of‑service condition. The weakness aligns with CWE‑494, where a program reads or executes code from an untrusted source without sufficient validation.
Affected Systems
The affected product is NVIDIA NemoClaw for Linux. No specific version information is supplied in the advisory; all releases that use the vulnerable installation mechanism are potentially impacted.
Risk and Exploitability
The CVSS score of 8.1 signals high severity. EPSS information is unavailable, so the current exploitation probability cannot be determined. The vulnerability is not listed in CISA KEV, and there is no public exploit code reported. The likely attack vector is during installation, which could be local or remote if an attacker controls the installation media. The combination of high severity and the need for local installation access means that any user with the ability to install software is at risk.
OpenCVE Enrichment