Back
Over 2,000 Nvidia GPU Servers Exposed by DCGM Exporter Flaw
SiTech AI Team2 min read

Over 2,000 Nvidia GPU Servers Exposed by DCGM Exporter Flaw

Researchers found over 2,000 Nvidia GPU servers exposing the DCGM Exporter monitoring tool to the web without authentication. The flaw let unauthenticated attackers crash the service and potentially disrupt AI workloads.

Flaw in Nvidia monitoring tool left GPU servers open

Researchers from cybersecurity company Lava discovered a high-severity flaw in Nvidia's DCGM Exporter, a tool that reads telemetry from GPUs on a host, including hardware information, memory usage and utilization, power consumption, and error events. The bug, tracked as CVE-2026-47483 and rated 8.2 on the CVSS scale, allowed an unauthenticated attacker to trigger uncontrolled resource consumption on the GPU server, leading to denial of service and information disclosure.

By exhausting the exporter's resources, an attacker could crash the monitoring service, blind operators to GPU health and activity, and potentially slow workloads running on the same host, Lava said. In total, the researchers found more than 2,000 GPU servers exposing the DCGM Exporter directly to the web without authentication.

Exposed hardware spanned AI data centers and consumer PCs

The exposed systems included Nvidia Blackwell Ultra B300 GPUs, H200s and H100s used for large-scale AI workloads, as well as consumer RTX 5090 and 4090 systems. Anyone who could reach these endpoints could see what hardware organizations were running, how heavily it was being used, and details about the AI infrastructure around it.

Together, the exposed GPUs represented around $100 million in hardware and belonged to about 300 organizations, nearly half of them located in the US.

Nvidia confirmed the issue and released a fix

Lava reported the issue to Nvidia, which agreed the problem was real and soon released a fix for the flaw. "Neoclouds are racing to add GPU capacity, and customers are racing to use it," said Yakir Kadkoda, CTO and Co-Founder at Lava. "That speed is creating security gaps on both sides - providers are moving faster than they can harden the environment, while customers often don't know exactly what they're inheriting or exposing."

"The findings highlight a growing security gap in AI infrastructure: companies are spending millions on GPUs while leaving critical systems exposed," Lava wrote. "Those exposures can reveal how AI environments are built and, in some cases, allow attackers to disrupt them."

Sources: Cybernews

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.