GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Isaac Launchable: Hard-coded credentials in Isaac Launchable give an unauthenticated network attacker code

CVE-2025-33222NVIDIA / GPU stackcurated

Impact

Hard-coded credentials in Isaac Launchable give an unauthenticated network attacker code execution and privilege escalation - scored 9.8. Hard-coded credentials are unpatchable by configuration: the fix has to be a new build, and any deployment still running the old artifact stays exploitable regardless of what you change around it.

Who can reach it

Network, unauthenticated, no user interaction. The credentials are in the artifact, so anyone with the artifact has them.

What to do

Update to the fixed Isaac Launchable release per bulletin 5749 and rotate anything the embedded credential could reach. Cost: redeploy. Critically, patching alone is insufficient - assume the credential is public and revoke it.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.