Impact
NVIDIA NeMo Speech contains a flaw in its speech data explorer component that permits an attacker to create malicious data files. Loading such data can trigger remote code execution. The exploitation may lead to privilege escalation, data disclosure, and tampering.
Affected Systems
The vulnerability is active in all platforms that ship the current NVIDIA NeMo Speech distribution. The vendor has not published specific version or build numbers that exclude the flaw, so any installation of NeMo Speech that includes the data explorer feature is impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is not available, so the probability of exploitation remains uncertain. The flaw allows remote execution via crafted data. The vulnerability is not listed in the CISA KEV catalog, but that does not preclude active exploitation. Based on the description, it is inferred that attackers only need to supply a malicious data file to the explorer to trigger code execution.
OpenCVE Enrichment