CVE-2026-0481Disclosure

LOWCVSS 9.2 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potentially resulting in loss of availability

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1327

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-15: 2Technical Details · 2026-05-15: 105-15
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - AMD Device Metrics Exporter Unrestricted IP Binding (CVE-2026-0481) Unrestricted IP address binding in the AMD Device Metrics Exporter (part of the ROCm ecosystem) exposes the gRPC server (port 50061) and ZeroMQ service (port 6601) on all network interfaces by default. This allows unauthenticated remote attackers to access the service and perform unauthorized changes to GPU configuration. The flaw can result in loss of availability and potential disruption of GPU operations in HPC/AI environments (CVSS 9.2 Critical). 👉Affected: AMD Device Metrics Exporter (ROCm 7.0.x & 7.1.x prior to fixed versions)

    Post summary

    AMD Device Metrics Exporter exposes its gRPC and ZeroMQ services over all interfaces, enabling unauthenticated remote attackers to alter GPU settings; the vulnerability is rated CVSS 9.2 Critical with no patch or evidence of exploitation yet.

    0001089
    196 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-0481 Unrestricted IP Address Binding in AMD Device Metrics Exporter ROC... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-0481 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The text merely references CVE-2026-0481 with a headline and a link to details, providing no actionable information about exploitation or mitigation.

    0000059
    4.0K followersView on X

Explore more