NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege escalation, data tampering, information disclosure, code execution, and denial of service.
The vulnerability (CWE-639) is based on the fact that the authorization system relies on a key that can be controlled by an attacker on the client side. An unauthorized attacker can manipulate this key in such a way as to gain access to resources or functions reserved for authorized users. The attack does not require any authentication, account possession, or interaction from the victim, and can be conducted remotely over the network.
An attacker can achieve privilege escalation, data modification (data tampering), disclosure of sensitive information (information disclosure), remote code execution (RCE), and denial of service (DoS) — potentially gaining complete control over the system.
Patches available from the manufacturer should be applied according to the references (https://nvidia.custhelp.com/app/answers/detail/a_id/5819). Until the fix is implemented, it is recommended to restrict network access to the NVFlare Dashboard interface exclusively to trusted hosts and internal networks.
NVIDIA NVFlare Dashboard running on Apple macOS and Linux (Linux Kernel); specific versions indicated in the manufacturer's references (https://nvidia.custhelp.com/app/answers/detail/a_id/5819)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApple macOS
OSAppleall versionsLinux Kernel
OSLinuxall versionsNvidia Nvflare
APPNvidia< 2.7.2
Related vulnerabilities
Pominięcie uwierzytelniania w Screen Sharing na macOS
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
Apple: Obejście Pointer Authentication w iOS, macOS i innych platformach