Most recent
navigate open esc close Corpus index built 2026-06-07 23:58 UTC

← All engagement records

Case study May 1, 2026

University of Manitoba: CS Department GPU Server, Deep Research Stack

Sector
Universities
Country
mb

NuClide Research · 2026-05-01


Summary

The Computer Science department at the University of Manitoba (quail.cs.umanitoba.ca) is running Ollama with five large local models including DeepSeek-R1:70B, Llama 3.3, and Llama 3:70B, a deep research stack totaling ~156GB of local models, all accessible without authentication.


Infrastructure

FieldValue
IP130.179.30.15
rDNSquail.cs.umanitoba.ca
OrgUniversity of Manitoba
DepartmentComputer Science
CountryCanada, Manitoba
Open ports11434 (Ollama, public)

Models

ModelSize
llama3.3:latest39 GB
llama3:70b37 GB
deepseek-r1:70b39 GB
qwen2.5-coder:32b18 GB
smollm2:135m0 GB

Total local compute: ~133 GB across 5 models.


Findings

F1, Unauthenticated CS Research Server (HIGH): Named GPU server in CS department. Research models (DeepSeek-R1, large Llama) and code model (Qwen2.5-Coder) exposed to the public internet.

F2, Model Injection (HIGH): All 5 models injectable via CVE-2025-63389, attacker can overwrite system prompts, affecting any research workflows using this Ollama instance.


Disclosure

  • Discovered: 2026-05-01
  • Status: Pending outreach to UManitoba IT / csirt@canarie.ca (CANARIE)