NVIDIA NVFlare Dashboard
cpe:2.3:a:nvidia:nvflare:*:*:*:*:*:*:*
- < 2.7.2
A vulnerability has been identified in the user management and authentication system of the NVIDIA NVFlare Dashboard. This issue allows an unauthenticated attacker to bypass authorization using user-controlled keys. Exploitation of this vulnerability could lead to privilege escalation, data tampering, unauthorized information disclosure, remote code execution, and denial-of-service conditions.
Successful exploitation allows for authorization bypass, leading to privilege escalation, data tampering, information disclosure, code execution, and denial-of-service.
Users are advised to update to NVIDIA NVFlare SDK version 2.7.2 or later. The updated version can be downloaded from the NVIDIA NVFlare GitHub repository.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.