GPU VulnDB

Database/NVIDIA / GPU stack

Base Command Manager (CMDaemon): Unauthenticated RCE on the cluster manager

CVE-2024-0138NVIDIA / GPU stackcurated

Impact

Unauthenticated RCE on the cluster manager -> full cluster takeover

Who can reach it

Network-adjacent unauthenticated attacker reaching CMDaemon

What to do

Emergency: patch Base Command Manager, restrict CMDaemon to the mgmt network, audit for compromise; cluster-wide credential rotation

Fleet impact

How widespread

Common - Base Command / Bright Cluster Manager is the control plane on many enterprise and neocloud GPU clusters

Cost to remediate

daemon-restart of the cluster control plane, which is itself a scheduling outage for the whole cluster

Why it hits the whole fleet

Missing authentication in CMDaemon, remotely exploitable with no user interaction or privileges: compromising the cluster manager means owning provisioning for every node in the cluster at once

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.