Impact
The vulnerability is a missing authorization control (CWE-862) in NVIDIA Triton Inference Server for Linux. An attacker could take advantage of the lack of authentication and send privileged commands to the server’s API endpoints without credentials. This could result in sensitive information being exposed, manipulation of inference model parameters or outputs, and disruption of service operations, as noted in the official description of possible information disclosure, data tampering, and denial of service. The impact is therefore primarily data confidentiality, integrity, and availability for any systems relying on the inference service.
Affected Systems
Vendor NVIDIA; product Triton Inference Server; platform Linux. Specific affected versions were not disclosed in the advisory; any unpatched instance is assumed vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker can exploit the server remotely by interacting with exposed API endpoints without authentication. The absence of an authorization control makes such exploitation straightforward for any adversary with network reach to the server, raising the risk to environments where the inference service is exposed to untrusted networks.
OpenCVE Enrichment