Sceawere

Vulnerability Detail

CVE-2026-24185UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

NVIDIA NVOS SSH Authentication Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
NVIDIA
Product
NVOS
Attack Type
CWE-288 Authentication Bypass Using an Alternate Path or Channel
Vector String
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could inadvertently enable an alternative authentication path. If best practices for replacing the default password as recommended by NVIDIA are not followed, this alternative authentication path might lead to unauthorized access. A successful exploit of this vulnerability might lead to escalation of privileges.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-08-18T19:16:46.410Z",
  "pubdate": "2026-08-18T19:16:46.410Z",
  "executiveSummary": "A vulnerability has been identified in the secure shell (SSH) server configuration component of NVIDIA NVOS for network switches when PKA-only mode is enabled.\nThe flaw allows an administrator to inadvertently enable an alternative authentication path, which, if combined with the failure to follow best practices for replacing default passwords, may lead to unauthorized access and escalation of privileges.\nThe affected product is NVIDIA NVOS for network switches.\nThe risk implications involve potential compromise of network infrastructure devices through unauthorized administrative access.\nAn attacker or administrator must interact with misconfigured SSH server settings where PKA-only mode and default credentials intersect to exploit the weakness.\nExploitation requirements include the presence of the alternative authentication path and failure to replace default passwords as recommended by NVIDIA.",
  "technicalDetails": "The vulnerability resides within the secure shell (SSH) server configuration component of NVIDIA NVOS for network switches.\nThe root cause stems from logic handling within the SSH server configuration when public key authentication (PKA) only mode is enabled, which inadvertently creates an alternative authentication path.\nIf administrators do not follow security best practices to replace default passwords as explicitly recommended by NVIDIA, this alternative path permits authentication mechanisms that bypass intended strict PKA-only restrictions.\nThe attack flow begins when the SSH server configuration incorrectly processes authentication requests via the alternative path due to the residual or default password state.\nAn entity leveraging this condition can authenticate using fallback or default credentials that should otherwise be rendered inert or inaccessible under strict PKA-only enforcement.\nSuccessful exploitation requires network exposure to the SSH server component and relies upon the pre-existence of default passwords on the affected network switch.\nThe post-exploitation impact includes unauthorized access to the network switch operating system and subsequent escalation of privileges, potentially granting full administrative control over the targeted network device."
}
CVE-2026-24185: NVIDIA NVOS SSH Authentication Bypass (HIGH Severity, CVSS: 7.1) - Sceawere