NVIDIA NeMo Framework
cpe:2.3:a:nvidia:nemo:*:*:*:*:*:*:*
- < 2.3.2
A code injection vulnerability has been identified in the NVIDIA NeMo library for all platforms, specifically within the model loading component. This issue allows an attacker to inject malicious code by loading .nemo files that contain carefully crafted metadata. Exploiting this vulnerability could result in remote code execution and unauthorized data modification.
Successful exploitation allows for remote code execution and data tampering.
Users are advised to upgrade to the latest version of the NVIDIA NeMo Framework, version 2.3.2 or later. This update is available on the NVIDIA GitHub Releases page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.