NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where a user can inject forged logs and executable commands by injecting arbitrary data as a new log entry. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
The vulnerability (CWE-117 — Improper Output Neutralization for Logs) consists of insufficient sanitization of data written to server logs. An attacker can inject crafted data that is interpreted as new log entries or executable commands. This mechanism can be exploited remotely over the network without user interaction, although it requires high-level privileges (PR:H). The scope of the vulnerability extends beyond the source component (Scope: Changed), which increases the potential attack reach.
An attacker can achieve arbitrary code execution (RCE), cause denial of service (DoS), escalate privileges, gain unauthorized access to information, and manipulate data in the system.
Apply patches available from the manufacturer according to references published by NVIDIA at https://nvidia.custhelp.com/app/answers/detail/a_id/5546
NVIDIA Triton Inference Server in versions for Linux and Windows systems — specific versions indicated in manufacturer references (https://nvidia.custhelp.com/app/answers/detail/a_id/5546)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:HLinux Kernel
OSLinuxall versionsMicrosoft Windows
OSMicrosoftall versionsNvidia Triton Inference Server
APPNvidia20.10 – 24.05 (excl.)
Related vulnerabilities
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
Path Traversal w Kingsoft WPS Office — ładowanie dowolnej biblioteki Windows
PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit