DGX Spark: Hardcoded credentials in config
CVSS 8.1CVE-2026-24218NVIDIA / GPU stackcurated
Impact
Hardcoded credentials in config -> unauthorized access
Who can reach it
Local or network attacker with config access
What to do
Update DGX Spark software; rotate all affected credentials
References
Related entries
- AI Tensor Engine for ROCm (AITER) - MessageQueue.recv() in shm_broadcast.py: AITER's MessageQueue.recv() deserialisesCVE-2026-49121 · AI Tensor Engine for ROCm (AITER) - MessageQueue.recv() in shm_broadcast.pyHigh
- DGX H100 BMC (KVM daemon): Session token theft via timing side channelCVE-2023-25529 · DGX H100 BMC (KVM daemon)High
- DGX H100 BMC (KVM): Code execution + privescCVE-2023-25530 · DGX H100 BMC (KVM)High
- Triton Inference Server: RCE / privesc via input-validation failureCVE-2025-23268 · Triton Inference ServerHigh
- Cumulus Linux / NVOS: Privesc to switch adminCVE-2025-33179 · Cumulus Linux / NVOSHigh
- Cumulus Linux / NVOS: Command injectionCVE-2025-33180 · Cumulus Linux / NVOSHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.