{"id":9964,"date":"2026-10-09T12:35:26","date_gmt":"2026-10-09T12:35:26","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9964"},"modified":"2026-10-09T12:35:26","modified_gmt":"2026-10-09T12:35:26","slug":"exposed-nvidia-gpu-monitors-can-reveal-ai-infrastructure-secrets","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9964","title":{"rendered":"Exposed Nvidia GPU monitors can reveal AI infrastructure secrets"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column \">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">A component of Nvidia\u2019s GPU monitoring software that enterprises use to keep tabs on their AI training and inference infrastructure has been vulnerable to denial-of-service (DoS) and information disclosure attacks.<\/p>\n<p class=\"wp-block-paragraph\">The Nvidia DCGM Exporter contains an unauthenticated resource exhaustion vulnerability that could allow remote attackers to crash the monitoring service and potentially disrupt AI workloads running on the same host. <\/p>\n<p class=\"wp-block-paragraph\">Nvidia released a <a href=\"https:\/\/github.com\/NVIDIA\/dcgm-exporter\/releases\/tag\/4.5.3-4.8.2\" target=\"_blank\" rel=\"noopener\">fix<\/a> for the flaw in May when researchers at Lava Security found thousands of DCGM Exporter instances reachable from the internet, with about a quarter of them exposing the profiling endpoints associated with the vulnerability.<\/p>\n<p class=\"wp-block-paragraph\">\u201cDuring our research, we found more than 2,000 GPU servers exposing Nvidia DCGM Exporter directly to the public internet without authentication,\u201d Lava researcher Michael Katchinskiy said in a <a href=\"https:\/\/lava.security\/research\/cve-2026-47483-nvidia-dcgm-exporter-vulnerability\" target=\"_blank\" rel=\"noopener\">blog post<\/a>. \u201cAcross four scans, those servers reported more than 12,000 unique GPUs, representing an estimated $100 million in hardware.\u201d<\/p>\n<p class=\"wp-block-paragraph\">DCGM Exporter is a telemetry agent Nvidia uses to collect metrics from <a href=\"https:\/\/www.csoonline.com\/article\/4022877\/alert-nvidia-gpus-are-vulnerable-to-rowhammer-attacks.html\">Nvidia GPUs<\/a> and make them available to monitoring systems such as Prometheus. Lava had reported the flaw to Nvidia, which had assigned it <a href=\"https:\/\/nvidia.custhelp.com\/app\/answers\/detail\/a_id\/5857\">CVE-2026-47483<\/a> with a high severity rating of CVSS 8.2.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Exposed profiling endpoints led to monitoring crashes<\/h2>\n<p class=\"wp-block-paragraph\">The problem lies in the way an unpatched DCGM Exporter handles concurrent, unauthenticated requests to its \u201c\/debug\/pprof\/\u201d profiling endpoints. A large number of concurrent profiling requests can drive memory consumption high enough to exhaust resources and crash the exporter.<\/p>\n<p class=\"wp-block-paragraph\">The immediate consequence is a loss of visibility into GPU health and activity, Lava said. But the potential impact is not necessarily limited to monitoring because the exporter shares a host with GPU workloads, Katchinskiy noted in the blog post. The CPU and memory pressure could also affect AI training or inference processes running alongside it.<\/p>\n<p class=\"wp-block-paragraph\">Nvidia\u2019s security bulletin classifies CVE-2026-47483 as an uncontrolled resource-consumption vulnerability, identifying DCGM Exporter version 4.8.2 as the updated version addressing the issue.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Telemetry could be used for reconnaissance<\/h2>\n<p class=\"wp-block-paragraph\">Nvidia DCGM Exporter collects <a href=\"https:\/\/www.csoonline.com\/article\/4215392\/gputhor-hardware-attack-can-root-nvidia-gpu-systems.html\">GPU telemetry<\/a>, including utilization, memory usage, power consumption, and error events, and exposes the metrics over HTTP for monitoring platforms such as Prometheus to scrape.<\/p>\n<p class=\"wp-block-paragraph\">When publicly accessible without authentication, these endpoints could reveal a lot about an organization\u2019s computing infrastructure, Lava says. The systems that were found exposed included Nvidia Blackwell Ultra B300 GPUs, H200s and H100s used for large-scale AI workloads, as well as consumer RTX 5090 and 4090 systems.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAnyone who could reach these endpoints could see what hardware organizations were running, how heavily it was being used, and details about the AI infrastructure around it,\u201d Katchinskiy warned. While such information does not provide access to model weights, training data, or other protected assets, it can help an attacker profile a target and identify weaker components or software versions.<\/p>\n<p class=\"wp-block-paragraph\">Lava has recommended restricting public access to DCGM Exporter and Prometheus unless external access is necessary, binding exporters to loopback or private interfaces, and enforcing access controls through firewalls, security groups, or other network measures. <\/p>\n<p class=\"wp-block-paragraph\">These steps should follow upgrading to version 4.8.2 or later and verifying that the \u201c\u2013enable\u2013pprof\u201d option is disabled. Katchinskiy noted that this profiling feature may be enabled by default in unpatched software.<\/p>\n<p class=\"wp-block-paragraph\">\n<\/p><\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A component of Nvidia\u2019s GPU monitoring software that enterprises use to keep tabs on their AI training and inference infrastructure has been vulnerable to denial-of-service (DoS) and information disclosure attacks. The Nvidia DCGM Exporter contains an unauthenticated resource exhaustion vulnerability that could allow remote attackers to crash the monitoring service and potentially disrupt AI workloads [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9965,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9964","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9964"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9964"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9964\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9965"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9964"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9964"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9964"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}