Impact
NVIDIA NeMo Speech contains a deserialization flaw (CWE-502) that allows an attacker to craft malicious data and trigger remote code execution. The successful exploitation can lead to arbitrary code execution, disclosure of sensitive information, and alteration of data, compromising both confidentiality and integrity. The attack requires the attacker to supply the malformed data to the NeMo service; the likely vector is data ingestion, which could be over a network interface or from local input, but the exact method is not detailed and is inferred from the need for malicious data.
Affected Systems
All platforms running NVIDIA NeMo Speech are affected, as version information is not specified in the advisory. Users of any supported build should treat the product as vulnerable until an official patch is released.
Risk and Exploitability
The CVSS score of 7.8 classifies this vulnerability as high severity, indicating significant impact if exploited. EPSS information is unavailable, so the precise likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog, which suggests no known widespread exploitation yet. The path to exploitation involves delivering crafted data that triggers the deserialization logic, a technique that has been successfully used in other contexts to achieve RCE.
OpenCVE Enrichment