Impact
The vulnerability arises from a missing authentication check in the inference server module of NVIDIA NemoClaw for Linux. Because the server accepts requests from any networked party, a remote attacker can send inference queries and obtain model outputs or other sensitive data. The flaw can also be abused to exhaust server resources, causing a denial‑of‑service. The weakness is classified as CWE‑306, unauthorized use or failure to enforce authentication.
Affected Systems
The flaw affects NVIDIA NemoClaw running on Linux. No specific versions are identified in the advisory, so all currently released releases may be vulnerable until a patch is applied. The product name is NVIDIA NemoClaw Inference Server.
Risk and Exploitability
The CVSS score is 8.1, indicating a high severity. The EPSS score is unavailable, so current exploitation likelihood cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. An attacker only needs network access to the inference service endpoint; no privileged or local access is required. Because authentication is not enforced, the attack can be performed from any remote host that can reach the service.
OpenCVE Enrichment