Impact
The vulnerability in NVIDIA NeMo Speech allows maliciously crafted input to trigger a code injection that can lead to arbitrary code execution, information disclosure, or data tampering within the affected system. The weakness lies in insufficient validation of speech input, enabling the injection of executable commands. This flaw could compromise the confidentiality, integrity, and availability of the application or the host system if exploited.
Affected Systems
All platforms running NVIDIA NeMo Speech are affected. Specific version information is not provided in the available data.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the delivery of specially crafted speech input to an exposed API or processing endpoint, which may be reachable remotely or locally depending on deployment. A successful exploitation would give the attacker the ability to execute arbitrary commands with the privileges of the NeMo Speech process.
OpenCVE Enrichment