Impact
NVIDIA Transformers4Rec is vulnerable to improper deserialization of untrusted data. A successful exploit may allow an attacker to run arbitrary code in the context of the affected system, and could also lead to data tampering and information disclosure.
Affected Systems
The vulnerability affects NVIDIA Transformers4Rec. No specific version information is provided in the advisory, so all deployed instances of this product should be considered potentially impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, indicating it has not been widely reported as exploited. The likely attack vector is remote delivery of malicious serialized data, although the exact prerequisites are not detailed in the advisory. The impact remains significant due to the risk of code execution and data compromise.
OpenCVE Enrichment