CyberRota Analysis
AI-GeneratedThe vulnerability in the TabularTokenizer class of NVIDIA NeMo allows for the deserialization of untrusted .pkl files, potentially leading to code execution, data tampering, denial of service, and information disclosure. Organizations utilizing NVIDIA NeMo for machine learning applications should prioritize patching this issue to mitigate the risk of exploitation. Given the high severity rating, immediate action is recommended to protect sensitive data and system integrity.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacker-controlled .pkl file via pickle.load() without validation. A successful exploit of this vulnerability may lead to code execution, data tampering, denial of service, and information disclosure.
Related CVEs
Other vulnerabilities affecting the same vendor(s)