CRITICAL🇵🇱 Wersja polska

CVE-2024-0095

CVSS 9.0v3.1pub. 2024-06-13upd. 2025-09-26

NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where a user can inject forged logs and executable commands by injecting arbitrary data as a new log entry. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

🤖 AI Analysis
How it works

The vulnerability (CWE-117 — Improper Output Neutralization for Logs) consists of insufficient sanitization of data written to server logs. An attacker can inject crafted data that is interpreted as new log entries or executable commands. This mechanism can be exploited remotely over the network without user interaction, although it requires high-level privileges (PR:H). The scope of the vulnerability extends beyond the source component (Scope: Changed), which increases the potential attack reach.

Impact

An attacker can achieve arbitrary code execution (RCE), cause denial of service (DoS), escalate privileges, gain unauthorized access to information, and manipulate data in the system.

Mitigation & patch

Apply patches available from the manufacturer according to references published by NVIDIA at https://nvidia.custhelp.com/app/answers/detail/a_id/5546

Who is affected

NVIDIA Triton Inference Server in versions for Linux and Windows systems — specific versions indicated in manufacturer references (https://nvidia.custhelp.com/app/answers/detail/a_id/5546)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H
  • Linux Kernel

    OS
    Linux
    all versions
  • Microsoft Windows

    OS
    Microsoft
    all versions
  • Nvidia Triton Inference Server

    APP
    Nvidia
    20.10 – 24.05 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDoS
CWE
References

Related vulnerabilities

CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product

Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP

CVE-2024-7262CRITICAL9.3⚠ KEVPL ✓same product

Path Traversal w Kingsoft WPS Office — ładowanie dowolnej biblioteki Windows

CVE-2024-4577CRITICAL9.8⚠ KEVPL ✓same product

PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit