CVE-2026-24185
Last modified
CVE-2026-24185 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could inadvertently enable an alternative authentication path. If best practices for replacing the default password as recommended by NVIDIA are not followed, this alternative authentication path might lead to unauthorized access. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could inadvertently enable an alternative authentication path. If best practices for replacing the default password as recommended by NVIDIA are not followed, this alternative authentication path might lead to unauthorized access. A successful exploit of this vulnerability might lead to escalation of privileges.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| NVIDIA | NVOS | 0.0 to 25.0.2.4438 |
| NVIDIA | NVOS | 0.0 to 25.0.2.6077 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-24185?
How severe is CVE-2026-24185?
How do I fix CVE-2026-24185?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-2418The Login with Salesforce WordPress plugin through 1.0.2 doe…9.1
- CVE-2026-24180NVIDIA DALI contains a vulnerability in a component where an…7.3
- CVE-2026-24181NVIDIA DALI contains a vulnerability in a component where an…7.3
- CVE-2026-24182NVIDIA Display Driver for Windows and Linux contains a vulne…6.5
- CVE-2026-24183NVIDIA Cumulus Linux contains a vulnerability in the user ma…7.8
- CVE-2026-24184NVIDIA Cumulus Linux contains a vulnerability in the Link La…8.8
- CVE-2026-24186NVIDIA FLARE SDK contains a vulnerability in FOBS, where an…8.8
- CVE-2026-24187NVIDIA Display Driver for Linux contains a vulnerability whe…8.8
- CVE-2026-24188NVIDIA TensorRT contains a vulnerability where an attacker c…7.5
- CVE-2026-24189NVIDIA CUDA-Q contains a vulnerability in an endpoint, where…8.2
- CVE-2026-2419The WP-DownloadManager plugin for WordPress is vulnerable to…2.7
- CVE-2026-24190NVIDIA Display Driver for Windows and Linux contains a vulne…7.8
Are you affected by CVE-2026-24185?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
