High-severity Nvidia bug could crash GPU monitoring on exposed servers
Researchers discovered thousands of Nvidia GPU servers exposed to the internet through a high-severity vulnerability in the DCGM monitoring service. The flaw allows unauthenticated attackers to crash monitoring and disrupt AI workloads, highlighting a serious security gap in AI infrastructure investment. Critical systems were left exposed without authentication, creating significant risk.
Researchers found approximately 2,100 exposed GPU servers with 12,000 GPU identifiers across 300 organisations between March and May, with 44 percent located in the US. The exposed hardware was worth around $100 million and included high-value Nvidia Blackwell Ultra B300, H200 and H100 GPUs used for large-scale AI operations. Nvidia released a fix in version 4.8.2 with an 8.2 CVSS severity rating, affecting major GPU cloud providers including Nebius, Voltage Park, Lambda, Northern Data and DigitalOcean.
- Thousands of Nvidia GPU servers exposed to the internet without authentication
- High-severity flaw could crash monitoring services and disrupt AI workloads
- $100 million worth of hardware at risk across 300 organisations
New here? Start with this
Nvidia produces specialist processors called GPUs that are essential for building artificial intelligence systems. These GPUs run monitoring software called DCGM that tracks their health and performance, but researchers discovered a serious security flaw allowing unauthorised people to crash these systems without needing any password.
Around 2,100 servers with thousands of these GPUs were left exposed to the internet without password protection across approximately 300 organisations. The exposed hardware was worth around $100 million and included some of Nvidia's most powerful processors used for intensive AI workloads. An attack could crash the monitoring system and disrupt the critical work these organisations depend on.
Several major cloud computing companies that hire out GPU access were affected, including DigitalOcean and Lambda. Nvidia released a security fix in version 4.8.2 of its DCGM software to address the vulnerability. Organisations have now been able to update their systems and protect their hardware.