NVIDIA NeMo Framework
cpe:2.3:a:nvidia:nemo:*:*:*:*:*:*:*
- < 2.5.1
A vulnerability exists in the NVIDIA NeMo framework prior to version 2.5.1, where a predefined variable can be exploited to include functionality from an untrusted control sphere. This vulnerability could lead to unauthorized code execution.
Exploitation of this vulnerability allows for arbitrary code execution on the affected system.
Users are advised to update to version 2.5.1 or later. The updated version is available on the NVIDIA NeMo GitHub repository and through the Python Package Index (PyPI).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.