NVIDIA and Northern Data: High-severity NVIDIA vulnerability lets unauthenticated attackers crash GPU monitoring

NVIDIA and Northern Data: High-severity NVIDIA vulnerability lets unauthenticated attackers crash GPU monitoring

NVIDIA DCGM Exporter Flaw Exposes Thousands of GPU Servers to Remote Attacks

A high-severity vulnerability (CVE-2026-47483) in NVIDIA’s DCGM Exporter a GPU monitoring tool left over 2,000 internet-exposed servers vulnerable to unauthenticated attacks, potentially disrupting AI and machine learning workloads. Discovered by security firm Lava and reported to NVIDIA, the flaw was assigned a CVSS score of 8.2 and patched in version 4.8.2, with a security bulletin released on July 28, 2026.

DCGM Exporter collects GPU metrics such as utilization, temperature, and power consumption and exposes them via HTTP (typically port 9400) for tools like Prometheus. However, Lava researcher Michael Katchinskiy found that exposed endpoints revealed sensitive details, including GPU models, unique IDs, and operational status, allowing attackers to profile hardware usage and identify potential targets.

Between March and May 2026, Lava’s scans uncovered more than 12,000 unique GPUs across nearly 300 organizations, with an estimated value of $100 million. The exposed hardware included high-end AI-focused GPUs like NVIDIA’s Blackwell Ultra B300, H200, and H100, as well as consumer-grade RTX 5090 and 4090 cards. The U.S. accounted for 44% of exposed GPUs (5,274), followed by Romania (2,054) and China (1,967). Some instances ran on cloud infrastructure from providers like Voltage Park, Lambda, Northern Data, and DigitalOcean, with Voltage Park confirming that affected deployments were customer-managed.

Beyond information disclosure, the flaw enabled denial-of-service (DoS) attacks. Roughly a quarter of exposed hosts also served Go’s /debug/pprof/ profiling endpoints, which could be exploited to exhaust memory and crash the exporter. Without authentication, attackers could flood these endpoints with concurrent requests, disrupting GPU monitoring and potentially degrading performance for AI workloads on the same host.

Lava’s investigation also revealed risks from Prometheus Node Exporter, which exposed server and network details including InfiniBand adapter models, firmware versions, and OS/kernel information on 12,096 public hosts. Combined with DCGM Exporter data, attackers could map GPU activity to specific servers and networks, increasing the risk of targeted exploits.

NVIDIA’s patch disables the profiling endpoint by default, but organizations are advised to upgrade to DCGM Exporter 4.8.2 or later and restrict monitoring services to private networks. The incident highlights the broader risk of exposed telemetry tools, which can provide attackers with granular insights into AI infrastructure and enable disruptive attacks.

Source: https://www.helpnetsecurity.com/2026/10/09/nvidia-dcgm-exporter-vulnerability-cve-2026-47483/

Northern Data cybersecurity rating report: https://www.rankiteo.com/company/northerndata

NVIDIA cybersecurity rating report: https://www.rankiteo.com/company/nvidia

"id": "NORNVI1791555937",
"linkid": "northerndata, nvidia",
"type": "Vulnerability",
"date": "3/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Nearly 300 organizations using '
                                              'NVIDIA GPUs',
                        'industry': 'Semiconductors, AI, GPU Manufacturing',
                        'location': 'Global (Headquartered in Santa Clara, '
                                    'USA)',
                        'name': 'NVIDIA',
                        'size': 'Large Enterprise',
                        'type': 'Technology Company'},
                       {'customers_affected': 'Customer-managed deployments',
                        'industry': 'Cloud Computing, AI Infrastructure',
                        'location': 'USA',
                        'name': 'Voltage Park',
                        'type': 'Cloud Infrastructure Provider'},
                       {'industry': 'Cloud Computing, AI Infrastructure',
                        'location': 'USA',
                        'name': 'Lambda',
                        'type': 'Cloud Infrastructure Provider'},
                       {'industry': 'Cloud Computing, AI Infrastructure',
                        'location': 'Germany',
                        'name': 'Northern Data',
                        'type': 'Cloud Infrastructure Provider'},
                       {'industry': 'Cloud Computing',
                        'location': 'USA',
                        'name': 'DigitalOcean',
                        'size': 'Large Enterprise',
                        'type': 'Cloud Infrastructure Provider'}],
 'attack_vector': 'Exposed HTTP endpoints (port 9400), /debug/pprof/ profiling '
                  'endpoints',
 'data_breach': {'sensitivity_of_data': 'High (infrastructure details, '
                                        'hardware profiling)',
                 'type_of_data_compromised': 'GPU metrics (utilization, '
                                             'temperature, power consumption), '
                                             'GPU models, unique IDs, '
                                             'operational status, InfiniBand '
                                             'adapter models, firmware '
                                             'versions, OS/kernel information'},
 'date_detected': '2026-03-01',
 'date_publicly_disclosed': '2026-07-28',
 'date_resolved': '2026-07-28',
 'description': 'A high-severity vulnerability (CVE-2026-47483) in NVIDIA’s '
                'DCGM Exporter, a GPU monitoring tool, left over 2,000 '
                'internet-exposed servers vulnerable to unauthenticated '
                'attacks, potentially disrupting AI and machine learning '
                'workloads. The flaw enabled information disclosure and '
                'denial-of-service (DoS) attacks, exposing sensitive GPU '
                'metrics and system details.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'exposed sensitive infrastructure '
                                       'details',
            'data_compromised': 'GPU models, unique IDs, operational status, '
                                'InfiniBand adapter models, firmware versions, '
                                'OS/kernel information',
            'downtime': 'Potential disruption of GPU monitoring and AI '
                        'workloads',
            'operational_impact': 'Degraded performance for AI and machine '
                                  'learning workloads, potential crashes due '
                                  'to DoS attacks',
            'systems_affected': 'Over 2,000 internet-exposed GPU servers, '
                                '12,000 unique GPUs'},
 'investigation_status': 'Resolved (patched)',
 'lessons_learned': 'Exposed telemetry tools can provide attackers with '
                    'granular insights into AI infrastructure, enabling '
                    'targeted exploits and disruptive attacks. Organizations '
                    'should restrict monitoring services to private networks '
                    'and ensure timely patching of vulnerabilities.',
 'post_incident_analysis': {'corrective_actions': 'Patch released to disable '
                                                  'profiling endpoint by '
                                                  'default, recommendations to '
                                                  'restrict monitoring '
                                                  'services to private '
                                                  'networks',
                            'root_causes': 'Exposed HTTP endpoints (port 9400) '
                                           'and /debug/pprof/ profiling '
                                           'endpoints without authentication, '
                                           'enabling information disclosure '
                                           'and DoS attacks'},
 'recommendations': ['Upgrade to DCGM Exporter 4.8.2 or later',
                     'Restrict monitoring services to private networks',
                     'Disable unnecessary profiling endpoints',
                     'Monitor for unauthorized access to telemetry tools'],
 'references': [{'date_accessed': '2026-07-28',
                 'source': 'NVIDIA Security Bulletin'},
                {'source': 'Lava Security Research'}],
 'response': {'communication_strategy': 'NVIDIA released a security bulletin '
                                        'on July 28, 2026',
              'containment_measures': 'NVIDIA released a patch (DCGM Exporter '
                                      '4.8.2) disabling the profiling endpoint '
                                      'by default',
              'network_segmentation': 'Recommended restriction of monitoring '
                                      'services to private networks',
              'remediation_measures': 'Upgrade to DCGM Exporter 4.8.2 or '
                                      'later, restrict monitoring services to '
                                      'private networks',
              'third_party_assistance': 'Lava (security firm)'},
 'title': 'NVIDIA DCGM Exporter Flaw Exposes Thousands of GPU Servers to '
          'Remote Attacks',
 'type': 'Information Disclosure, Denial-of-Service (DoS)',
 'vulnerability_exploited': 'CVE-2026-47483'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.