CVE-2024-0087 describes a vulnerability in NVIDIA Triton Inference Server for Linux, allowing a logged-in user to redirect logging to an arbitrary file, appending data if the file exists. This high-severity flaw (CVSS 8.8) is easily exploitable over the network with low privileges and no user interaction, potentially leading to code execution, denial of service, privilege escalation, information disclosure, or data tampering. While the vulnerability has garnered some community discussion and media coverage, there is currently no evidence of active exploitation, nor are public exploit tools like Metasploit or Nuclei available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 20.10, < 24.04CPE matchmatch criteria | cpe:2.3:a:nvidia:triton_inference_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.