CVE-2024-22476 is a critical improper input validation vulnerability in Intel Neural Compressor software versions prior to 2.5.0. This flaw allows an unauthenticated remote attacker to potentially achieve escalation of privilege. With a CVSS score of 10.0, it presents a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While not yet in the KEV catalog, exploit intelligence indicates the existence of Nuclei templates for SQL injection, and it has garnered significant community discussion and media coverage, suggesting high awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | Intel(R) Neural Compressor Software | before version 2.5.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.