Impact
NVIDIA NemoClaw for Linux includes a flaw in its migration command that allows a local attacker to inject and execute arbitrary code. This code injection vulnerability can result in code execution, data tampering, information disclosure, and denial of service. The weakness corresponds to CWE-94, an improper control of code generation.
Affected Systems
The affected product is NVIDIA NemoClaw running on Linux. No specific version details were provided, but any installation of the product is potentially compromised until a patched version is applied.
Risk and Exploitability
The CVSS score of 7 indicates medium severity for local exploitation. EPSS is not available, and the vulnerability is not listed in KEV. The likely attack vector is from a local user with privileges to run the migration command, as the description specifies a local attacker. Because the issue permits arbitrary code execution, the potential impact is significant should an attacker gain appropriate access.
OpenCVE Enrichment