MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-09 · via Help Net Security

NVIDIA monitoring tool flaw left thousands of GPUs exposed to denial-of-service attacks

Image via Help Net Security
Image via Help Net Security

NVIDIA's DCGM Exporter contained a high-severity bug, CVE-2026-47483, that could be crashed by attackers who did not need credentials, potentially disrupting AI workloads. Lava discovered more than 2,000 internet-facing servers during scans between March and May 2026, covering over 12,000 GPUs across nearly 300 organizations. NVIDIA gave the issue a CVSS score of 8.2 and released a security bulletin on July 28, 2026.

Expanded Detail

NVIDIA’s DCGM Exporter collects GPU telemetry—temperature, utilization, memory, power, and errors—and serves it over HTTP, usually port 9400, for Prometheus. Lava’s Michael Katchinskiy found over 2,000 internet-facing instances between March and May 2026, representing more than 12,000 GPUs across nearly 300 organizations. The flaw, CVE-2026-47483, received CVSS 8.2; NVIDIA issued a bulletin on July 28, 2026.

Roughly a quarter of exposed hosts also published Go /debug/pprof/ endpoints. Many simultaneous requests without credentials could exhaust memory and crash the exporter. Researchers also found 12,096 Node Exporter instances reachable publicly, revealing adapter and firmware identifiers, link status, host names, operating system, kernel, and BIOS information.

Context

If such monitoring endpoints remain exposed, outages could blind operators to GPU health, potentially slowing or interrupting AI training and inference. Organizations running shared GPU clouds, research labs, and enterprises may face service disruptions, troubleshooting delays, and higher operational costs. Because the flaw needs no credentials, opportunistic actors could trigger crashes, though the reported issue affects availability rather than direct data theft. The broader lesson may be that observability services need the same hardening as production systems.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Help Net Security →
Related stories
AI Agents Emerge as a New Target for Business Email Compromise Tactics · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “High-severity NVIDIA vulnerability lets unauthenticated attackers crash GPU monitoring.” Browse more stories.