CVE-2026-0481
Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potentially resulting in loss of availability
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.2
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
- EPSS probability
- 0.31%
- CWE
- CWE-1327
- Published
- 2026-05-15
- Last modified
- 2026-05-15
Affected products
- AMD AMD Instinct™ MI210
- AMD AMD Instinct™ MI250
- AMD AMD Instinct™ MI300A
- AMD AMD Instinct™ MI300X
- AMD AMD Instinct™ MI325X
- AMD AMD Instinct™ MI350X
- AMD AMD Instinct™ MI355X
- AMD AMD Instinct™ MI308X
Weakness type
Related vulnerabilities
- CVE-2026-75021 — fastify-cli vulnerable to remote code execution via ignored explicit Inspector bind address
- CVE-2026-20212 — Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Code Execution Vulnerability
- CVE-2026-82456 — argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTP
- CVE-2026-72924 — GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default
- CVE-2026-16713 — IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution
- CVE-2026-55641 — 9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
- CVE-2026-42503 — Accidental binding to INADDR_ANY might lead to RCE in golang.org/x/tools/gopls
- CVE-2026-24015 — Apache IoTDB: Insecure Default Configuration Vulnerability