PT-2026-42219 · Nvidia · Dgx Spark+1
CVE-2026-24218
·
Published
2026-05-20
·
Updated
2026-07-23
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NVIDIA DGX OS (affected versions not specified)
Description
A flaw in the factory provisioning process occurs when the cloning of a base image results in the deployment of identical SSH host keys across multiple systems. This sharing of cryptographic identifiers allows for host impersonation or attacker-in-the-middle attacks, where an attacker intercepts communication between two parties. Successful exploitation could lead to code execution, data tampering, privilege escalation, information disclosure, and denial of service.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dgx Spark
Dgx Os