What is CVE-2026-24185?
A vulnerability in NVIDIA NVOS for network switches involves the SSH server where, with PKA-only mode enabled, an administrator could inadvertently enable an alternative authentication path. This poses an unauthorized access risk if the default password is not changed. It is crucial to replace the default password and review the configuration as recommended by NVIDIA.
Azərbaycanca: NVIDIA NVOS şəbəkə açarları üçün SSH serverində, PKA-only rejimi aktiv olduqda administratorun alternativ autentifikasiya yolunu səhvən aktivləşdirə bilməsi boşluğu aşkarlanıb. Bu, default parol dəyişdirilmədikdə icazəsiz giriş riski yaradır. NVIDIA-nın tövsiyə etdiyi kimi default parolu dəyişdirmək və konfiqurasiyanı yoxlamaq lazımdır.
Related CVEs
link basis: same weakness class CWE-1188
FAQ2
Can CVE-2026-24185 be exploited only when PKA-only SSH mode is enabled?
Yes, the vulnerability occurs specifically when an administrator inadvertently enables an alternative authentication path in the NVIDIA NVOS SSH server while PKA-only mode is active.
What is the primary mitigation for CVE-2026-24185?
NVIDIA recommends replacing the default password and reviewing the SSH configuration to prevent unauthorized access related to this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.