Impact
NVIDIA TensorRT‑LLM for Linux contains a flaw in the disaggregated orchestrator component that allows an attacker to send requests to the FastAPI server, leading to the ability to read, write, or delete the internal cluster state. The vulnerability, rooted in the absence of authentication for critical functions, can result in information disclosure, data tampering, and service disruption. It is classified as CWE-306.
Affected Systems
All releases of NVIDIA TensorRT‑LLM for Linux that include the vulnerable orchestrator code are potentially affected. No specific version constraints are listed; any installation that incorporates the present code path may be susceptible.
Risk and Exploitability
The CVSS score of 7.3 indicates a high degree of impact. The EPSS score of less than 1% reflects a very low current probability of exploitation, and the vulnerability is not included in the CISA KEV catalog. Based on the description, it is inferred that exploitation would require remote access to the FastAPI endpoint, which lacks authentication; an attacker could craft and send malicious requests to manipulate the cluster state.
OpenCVE Enrichment