GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA AIStore - AuthN: A flaw in the AIStore authentication component reaches privilege escalation, information

CVE-2025-33186NVIDIA / GPU stackcurated

Impact

A flaw in the AIStore authentication component reaches privilege escalation, information disclosure and data tampering - effectively an authentication bypass in front of your training data store. Scored 8.8 network with no privileges required.

Who can reach it

Network, unauthenticated, one user-interaction step. Anyone with a route to AIStore's AuthN service.

What to do

Upgrade AIStore per bulletin 5724 as a priority and rotate AuthN tokens afterwards - the patch does not invalidate credentials an attacker may already hold. Cost: rolling control-plane restart.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.