Impact
A defect in the convPoolShapeInference_opset19 routine of the ONNX runtime triggers an out‑of‑bounds read (CWE‑119, CWE‑125) when processing particular ONNX model definitions. The vulnerability is exposed via the onnxruntime API. Based on the description, it is inferred that the attack vector involves supplying a malicious ONNX model that is loaded by the runtime during normal model handling.
Affected Systems
The vulnerability affects the ONNX library and its onnxruntime integration in all releases up to and including version 1.21.x. The affected code resides in onnx/defs/nn/old.cc, and systems that load ONNX models using the onnxruntime API are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score of < 1 % indicates a low overall likelihood of exploitation in the wild. The availability of a public exploit and the remote attack capability suggest that attackers could target vulnerable deployments. This inference points to a non‑zero but still low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment