Impact
NVIDIA Model-Optimizer is vulnerable to unsafe deserialization of untrusted data, which may allow an attacker to run arbitrary code, modify data, disrupt service availability, or leak sensitive information. The weakness is identified as CWE-502, a common deserialization flaw that can be leveraged to achieve these outcomes when an attacker controls the input stream.
Affected Systems
The vulnerability affects NVIDIA’s Model-Optimizer component. No specific version ranges are disclosed; therefore, users of any releases that have not yet been patched remain at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity level, and although no EPSS data is available, the potential for exploitation remains significant because the flaw permits code execution when untrusted data is processed. The vulnerability is not currently listed in the CISA KEV catalog, but its impact warrants close monitoring. The likely attack vector is through submission of crafted input to the Model-Optimizer, which could be achieved remotely if the service is exposed or locally if an attacker can supply input via an insider or compromised system.
OpenCVE Enrichment