Impact
NVIDIA NemoClaw contains a flaw that allows an attacker to trigger the execution of a process by exposing sensitive information in a visible way. If exploited, the attacker could gain unauthorized access to data that should remain confidential, resulting in a disclosure of information to which they are not entitled.
Affected Systems
The vulnerability impacts NVIDIA NemoClaw. No specific version numbers are listed in the advisory, so all deployments of the product are potentially affected until a patch is applied.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate risk. The EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not present in CISA’s KEV catalog. Based on the description, it is inferred that the attack could be performed by an entity that can observe or influence the process invocation path, potentially from a local or remote source depending on how the process trigger is exposed.
OpenCVE Enrichment