Impact
A flaw in NVIDIA TensorRT‑LLM’s visual generation server permits the deserialization of messages received through ZeroMQ without proper validation. An attacker capable of sending crafted ZeroMQ payloads can exploit this unsafe deserialization to trigger arbitrary code execution, as the vulnerability is a classic instance of CWE‑502. The description states that a successful exploitation may lead to code execution, indicating that the impact is full compromise of the system hosting the server.
Affected Systems
The vulnerability affects NVIDIA TensorRT‑LLM on any platform. No specific version numbers are listed, so the risk applies to all releases of the software until an official fix is applied.
Risk and Exploitability
The CVSS score of 6.4 denotes a medium severity, and the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is an unauthorized remote user who can reach the visual generation server and send a malicious ZeroMQ message, causing unsafe deserialization and potential code execution.
OpenCVE Enrichment