Impact
NVIDIA NemoClaw for Linux includes a flaw in its installation scripts where downloaded code is not verified for integrity. An attacker can use this weakness to have the installer download malicious code, leading to arbitrary code execution, privilege escalation, and potential information disclosure or data tampering. The underlying weakness corresponds to CWE-494, reflecting the absence of a proper integrity check. The likely attack vector is through manipulation of the installation environment or the source from which the installer retrieves its components, which is inferred from the description of missing integrity verification during code download.
Affected Systems
The affected product is NVIDIA NemoClaw on Linux platforms. Specific version information is not provided in the available data, so any publicly released version that includes the vulnerable installation scripts may be impacted.
Risk and Exploitability
The CVSS score for this vulnerability is 7.5, indicating a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The risk is elevated because an attacker who can modify the installation script, the repository source, or coerce a user to run a compromised installer can execute arbitrary code and elevate privileges. Exploitation would typically require access to the installation environment and the ability to direct the installer to download unverified code.
OpenCVE Enrichment