Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-33228

Опубликовано: 20 янв. 2026
Источник: redhat
CVSS3: 6.6
EPSS Низкий

Описание

NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplying a malicious string to the process_nsys_rep_cli.py script if the script is invoked manually. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.

A flaw was found in NVIDIA Nsight Systems. This vulnerability allows a local attacker to achieve arbitrary code execution by manually invoking the process_nsys_rep_cli.py script with a malicious string. This OS command injection can lead to privilege escalation, data tampering, denial of service, and information disclosure.

Отчет

This vulnerability is rated Important as it allows for OS command injection in NVIDIA Nsight Systems. The flaw occurs when the process_nsys_rep_cli.py script is manually invoked with a malicious string, potentially leading to code execution and privilege escalation. Red Hat Enterprise Linux systems with affected nsight-systems components are impacted if the script is used in this manner.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10cuda-nsight-systems-13-0Fix deferred
Red Hat Enterprise Linux 10cuda-nsight-systems-13-1Fix deferred
Red Hat Enterprise Linux 10nsight-systems-2025.3.2Fix deferred
Red Hat Enterprise Linux 10nsight-systems-2025.5.2Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2431292nsight-systems: Nsight Systems: Arbitrary code execution via OS command injection

EPSS

Процентиль: 66%
0.01206
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
7 месяцев назад

NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplying a malicious string to the process_nsys_rep_cli.py script if the script is invoked manually. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.

CVSS3: 7.3
nvd
7 месяцев назад

NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplying a malicious string to the process_nsys_rep_cli.py script if the script is invoked manually. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.

CVSS3: 7.3
debian
7 месяцев назад

NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot reci ...

CVSS3: 7.3
github
7 месяцев назад

NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplying a malicious string to the process_nsys_rep_cli.py script if the script is invoked manually. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.

EPSS

Процентиль: 66%
0.01206
Низкий

6.6 Medium

CVSS3