Impact
An attacker could cause the Triton Inference Server to perform excessive iterations, exhausting resources and preventing normal operation. The flaw is a resource exhaustion vulnerability, classified as CWE‑834. The description does not specify attack details, but the nature of the issue implies that malformed inference requests or a malicious client interacting with the inference service could trigger the excessive processing.
Affected Systems
The vulnerability affects NVIDIA Triton Inference Server for Linux installations. No specific product versions were listed, so any deployment of this server could be susceptible.
Risk and Exploitability
The CVSS score of 7.5 signals a high severity and indicates that, once exploited, the server could become unavailable to legitimate users. While the EPSS score is not available, the flaw is not listed in the CISA KEV catalog, suggesting no publicly known exploitation yet. The likely attack vector is an external or local client connecting to the inference API and sending crafted requests; the exploitability hinges on the ability to reach the server and provide input that triggers the resource consumption.
OpenCVE Enrichment