NVIDIA NVOS (network switches): With PKA-only SSH mode enabled, an administrator can inadvertently leave an alternative
Impact
With PKA-only SSH mode enabled, an administrator can inadvertently leave an alternative authentication path open. If the default password was never changed, that path grants unauthorised switch access - so the switch looks key-only while still accepting a known password.
Who can reach it
Network, adjacent, low privileges. The exposure only exists where the default password survived deployment, which is exactly the switch nobody revisited after racking.
What to do
Update NVOS per bulletin 5817 and, more importantly, verify that no switch still holds a default password - the configuration audit matters more than the patch here. Cost: switch reboot for the upgrade; the password audit costs nothing and should happen today.
References
Related entries
- vGPU Manager: Guest-to-host impact via invalid guest-driver inputCVE-2026-24195 · vGPU ManagerHigh
- GPU Display Driver: Info disclosure (OOB read of graphics memory)CVE-2026-24196 · GPU Display DriverHigh
- Linux kernel amdgpu user-mode queues (doorbell submission path) (drm/amdgpu): An out-of-bounds access in the amdgpuCVE-2026-31766 · Linux kernel amdgpu user-mode queues (doorbell submission path) (drm/amdgpu)High
- Linux kernel amdgpu firmware, ACPI and IP-block initialisation (drm/amdgpu/vcn4): An out-of-bounds access in the amdgpuCVE-2026-46199 · Linux kernel amdgpu firmware, ACPI and IP-block initialisation (drm/amdgpu/vcn4)High
- Linux kernel amdgpu firmware, ACPI and IP-block initialisation (drm/amdgpu/vcn4): An out-of-bounds access in the amdgpuCVE-2026-46204 · Linux kernel amdgpu firmware, ACPI and IP-block initialisation (drm/amdgpu/vcn4)High
- Linux kernel amdgpu firmware, ACPI and IP-block initialisation (drm/amdgpu): An out-of-bounds access in the amdgpuCVE-2026-46218 · Linux kernel amdgpu firmware, ACPI and IP-block initialisation (drm/amdgpu)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.