
Cloud Vulnerability DB
A community-led vulnerabilities database
NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability (CVE-2024-0095) where users can inject forged logs and executable commands by injecting arbitrary data as a new log entry. The vulnerability was discovered and disclosed in May 2024, affecting versions 20.10 through 24.04 of the Triton Inference Server (NVIDIA Security).
The vulnerability is classified as CWE-117 (Improper Output Neutralization for Logs) and has been assigned a CVSS v3.1 base score of 9.0 CRITICAL with the vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H. The vulnerability allows for arbitrary data injection as new log entries, which can be exploited to execute commands (NVD Database).
A successful exploitation of this vulnerability can lead to multiple severe consequences including code execution, denial of service, escalation of privileges, information disclosure, and data tampering. The vulnerability has been rated as having a Medium severity impact based on NVIDIA's risk assessment across diverse system installations (NVIDIA Security).
The vulnerability requires high privileges (PR:H) but has low attack complexity (AC:L) and needs no user interaction (UI:N) to exploit. It can be accessed over the network (AV:N), making it potentially exploitable in both local and remote attack scenarios (NVD Database).
NVIDIA has released version 24.05 of the Triton Inference Server to address this vulnerability. Users are advised to upgrade to this version immediately. Additionally, NVIDIA recommends that users deploying Triton Inference Server in production settings should follow the Secure Deployment Considerations Guide and ensure that logging and shared memory APIs are protected for use by authorized users only (NVIDIA Security).
The vulnerability was discovered and reported by security researcher pinkdraconian. NVIDIA has acknowledged and credited the researcher for reporting this security issue (NVIDIA Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."