Impact
NVIDIA TensorRT-LLM for Linux includes an authentication bypass that allows an attacker to invoke a critical function without proper validation. This flaw can result in arbitrary code execution, data tampering, and information disclosure. The vulnerability is classified as CWE-306, Missing Authentication, which directly compromises the confidentiality and integrity of the system by permitting unauthorized operations that should be restricted to authenticated users.
Affected Systems
The affected product is TensorRT-LLM on Linux. The advisory does not specify vulnerable releases, so all current and existing versions should be regarded as potentially affected until a vendor‑issued patch or update is released.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score of less than 1% suggests that the likelihood of exploitation in the wild is very small. The vulnerability is not listed in CISA's KEV catalog. The attack vector is inferred to involve local or remote exploitation of the unprotected function, with the attacker likely needing some degree of access to the system or the ability to trigger the function remotely, however the specific conditions are not detailed in the advisory.
OpenCVE Enrichment