NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where, when it is launched with the non-default command line option --model-control explicit, an attacker may use the model load API to cause a relative path traversal. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
2024-01-12T17:15:09.183
2024-11-21T08:01:17.673
Modified
CVSSv3.1: 7.5 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | nvidia | triton_inference_server | < 2.40 | Yes |
| Operating System | linux | linux_kernel | - | No |
| Operating System | microsoft | windows | - | No |