Impact
NVIDIA OpenShell for all platforms contains a command injection flaw that can be triggered by a malicious gateway. An attacker who exploits this weakness can run arbitrary OS commands, leading to code execution, data tampering, and information disclosure. The vulnerability is classified as CWE-78.
Affected Systems
Affected products are NVIDIA’s OpenShell on all supported platforms. No specific version numbers are disclosed, so any deployment of OpenShell may be vulnerable until it is updated.
Risk and Exploitability
The CVSS score of 8.8 signals high severity, and the EPSS value is unavailable, so the current exploitation likelihood remains uncertain. The vulnerability is not listed in CISA KEV, but its high severity suggests it is worth prioritizing. The likely attack vector is network‑based, involving a compromised or malicious gateway that sends crafted commands to the OpenShell service. An attacker would need network access or control over the gateway to leverage this flaw.
OpenCVE Enrichment