Impact
The vulnerability is an improper validation of array indices in NVIDIA TensorRT, a library used to accelerate deep‑learning inference. It allows malicious input to trigger out‑of‑bounds access, which may lead to arbitrary code execution within the process that loads TensorRT. The CVE explicitly notes that a successful exploit might result in code execution, but it does not provide details on the extent of control or whether the impact is local or remote.
Affected Systems
NVIDIA TensorRT is the only product listed as affected. No specific version ranges are provided, so all current releases remain potentially vulnerable until a vendor patch or advisory is issued. Organizations using TensorRT in applications or services should assume that any deployment could be at risk.
Risk and Exploitability
The CVSS v3 score of 7.8 indicates high severity, while the EPSS score of <1% suggests a low probability of exploitation at present. The CVE does not specify whether the flaw can be triggered remotely or requires local access; the most likely attack vector is that an attacker must provide malformed data to a TensorRT‑enabled component, which may be possible if the library processes data from untrusted sources. The vulnerability is not listed in CISA KEV, indicating no known widespread exploitation.
OpenCVE Enrichment