CVE-2024-35199 affects TorchServe, a tool for serving PyTorch models, where its gRPC ports (7070 and 7071) are inadvertently bound to all network interfaces instead of localhost by default. This vulnerability has a CVSS score of 8.2 (HIGH), indicating a network-based attack with low complexity, requiring no user interaction, and potentially leading to a loss of availability and limited confidentiality. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog. The issue is resolved in TorchServe release 0.11.0, and users are advised to upgrade as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.3.0, < 0.11.0CPE matchmatch criteria | cpe:2.3:a:pytorch:torchserve:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.