NVIDIA DGX OS Vulnerability in Factory Provisioning Process Leads to Security Risks
CVE-2026-24218
8.1HIGH
What is CVE-2026-24218?
The NVIDIA DGX OS suffers from a vulnerability in its factory provisioning process, where the cloning of a base image leads to multiple systems sharing the same SSH host keys. This shared cryptographic identifier poses a significant security risk as it allows for host impersonation and potential man-in-the-middle attacks. Exploiting this vulnerability can lead to unauthorized code execution, data manipulation, privilege escalation, information disclosure, and even denial of service, highlighting the urgent need for security measures in provisioning processes.
Affected Version(s)
DGX Spark NVIDIA DGX OS 0