Impact
The vulnerability is an improper certificate validation in the deployment process of NVIDIA NemoClaw for Linux. An attacker who controls the deployment mechanism can supply a forged certificate, bypass validation, and gain access that could lead to information disclosure, data tampering, possible code execution, and privilege escalation. The flaw is a classic certificate validation weakness, classed as CWE‑295.
Affected Systems
NVIDIA's NemoClaw for Linux is affected. No specific versions are listed in the advisory, so all current releases should be considered vulnerable until a patched version is released.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, implying no known public exploits yet. However, the failure occurs during deployment, a process often controlled by privileged users or continuous integration pipelines. An attacker who can influence deployment—such as a compromised build server or an insider with deployment rights—can craft a malicious certificate that bypasses validation, leading to the adverse impacts described.
OpenCVE Enrichment