Ethical Hacking News
High-severity Nvidia bug could crash GPU monitoring on exposed servers, leaving AI workloads vulnerable to disruption and potential attacks. Nvidia has released a fix for the bug, but companies must take proactive measures to secure their AI infrastructure.
Nvidia DCGM Exporter, a GPU health and performance monitoring service, has a high-severity bug (CVE-2026-47483) that can be accessed through the internet. The bug exposes critical system information, including GPU utilization, memory usage, and error events, making it vulnerable to reconnaissance and exploitation by attackers. About 2,100 GPU servers were found to be exposing DCGM Exporter metrics to the open internet, including 5,274 exposed GPUs in the US, valued at $100 million. Public Node Exporter hosts were also found to be exposing data on server models, operating systems, and firmware versions, which can be used for reconnaissance. Nvidia has released a fix for the bug, and companies are advised to upgrade to version 4.8.2 or later to prevent exploitation.
High-severity Nvidia bug could crash GPU monitoring on exposed servers
A recent discovery by researchers at datacenter security startup Lava has highlighted a significant security gap in AI infrastructure, where companies are spending millions on GPUs while leaving critical systems exposed. The bug, tracked as CVE-2026-47483, affects the GPU health and performance monitoring service, Nvidia DCGM Exporter, which can be accessed through the internet and provides detailed information about the hardware, utilization, memory usage, power consumption, and error events of each GPU on a host.
The exposure of this information can be used by attackers for reconnaissance, including mapping GPU infrastructure, identifying potentially vulnerable systems, and monitoring workload activity. This can potentially disrupt AI workloads and provide attackers with valuable insights into the AI environment, making it easier for them to launch targeted attacks.
The researchers found that about 2,100 GPU servers exposing DCGM Exporter metrics to the open internet, which includes 12,000 GPU UUIDs. These hosts belonged to about 300 organizations, with nearly half - 5,274 of the exposed GPUs, or 44 percent of the total - located in the US. The exposed GPUs represented about $100 million in hardware, including Nvidia Blackwell Ultra B300 GPUs, H200s, and H100s, used to run large-scale AI workloads, as well as consumer RTX 5090 and 4090 systems.
In addition to DCGM Exporter, the researchers also found that about 12,096 public Node Exporter hosts exposing data on server models, operating systems, firmware versions, hostnames, storage paths, and networking hardware commonly used in GPU clusters. This information can reveal how environments are built and configured, which could also be used by attackers for reconnaissance, matching the system to known vulnerabilities.
The discovery of this high-severity bug highlights the need for companies to take a closer look at the security of their AI infrastructure. Nvidia has released a fix for the bug, tracked as CVE-2026-47483, and operators are advised to upgrade to version 4.8.2 or later. However, the fact that this bug was able to be discovered and exploited highlights the need for more robust security measures to be put in place.
The researchers at Lava have emphasized the importance of restricting these monitoring services to authorized monitoring infrastructure and not making them directly reachable from the public internet. They have also reported all of the affected providers to the relevant authorities, and the providers have worked with customers to address the exposures.
In conclusion, the discovery of this high-severity Nvidia bug highlights the need for companies to take a closer look at the security of their AI infrastructure. The exposure of this information can be used by attackers for reconnaissance, including mapping GPU infrastructure, identifying potentially vulnerable systems, and monitoring workload activity. It is essential for companies to take robust security measures to prevent such vulnerabilities from being exploited.
Related Information:
https://www.ethicalhackingnews.com/articles/Exposing-the-Vulnerabilities-of-AI-Infrastructure-A-High-Severity-Nvidia-Bug-and-the-Risks-it-Poses-ehn.shtml
https://www.theregister.com/security/2026/10/08/high-severity-nvidia-bug-could-crash-gpu-monitoring-on-exposed-servers/5302077
https://nvd.nist.gov/vuln/detail/CVE-2026-47483
https://www.cvedetails.com/cve/CVE-2026-47483/
Published: Thu Oct 8 15:06:30 2026 by llama3.2 3B Q4_K_M