Impact
NVIDIA’s NemoClaw subsystem contains a flaw that allows credentials to be insufficiently protected. A successful exploitation of this vulnerability would enable an attacker to read confidential data and alter stored information. The weakness is identified as CWE‑522, indicating that sensitive credentials are not kept secure, and the impact is limited to the integrity and confidentiality of data handled by the affected component.
Affected Systems
The vulnerability affects NVIDIA NemoClaw devices. No specific version numbers are supplied in the public data, so all existing installations of NemoClaw should be treated as potentially impacted until a vendor update is confirmed.
Risk and Exploitability
The CVSS score of 5.6 reflects moderate risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation has not yet been observed. The likely attack vector is not explicitly stated in the advisory; based on the description, it is inferred that an attacker could manipulate credentials through local or remote interfaces that interact with NemoClaw, but no concrete method is detailed.
OpenCVE Enrichment