NVIDIA NVOS Vulnerability in SSH Server Configuration for Network Switches
CVE-2026-24185

7.1HIGH

Key Information:

Vendor

Nvidia

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-24185?

The NVOS software for NVIDIA network switches is vulnerable due to a misconfiguration in the secure shell (SSH) server component when the PKA-only mode is enabled. If administrators do not adhere to the best practices for changing the default password, this can result in an alternative authentication pathway being inadvertently activated. This misconfiguration poses a risk of unauthorized access and potential privilege escalation, highlighting the importance of following security protocols to mitigate such vulnerabilities.

Affected Version(s)

NVOS GB300 0.0 to 25.0.2.4438

NVOS IBSwitch XDR 0.0 to 25.0.2.6077

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.