First published: Tue Apr 22 2025(Updated: )
NVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA NeMo |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23249 is considered a high severity vulnerability due to its potential for remote code execution.
To mitigate CVE-2025-23249, ensure that you apply the latest security patches provided by NVIDIA for the NeMo Framework.
CVE-2025-23249 affects the NVIDIA NeMo Framework, which is used for building and training AI models.
Exploitation of CVE-2025-23249 can lead to remote code execution and potential data tampering on affected systems.
NVIDIA is responsible for addressing and providing updates related to the vulnerability identified as CVE-2025-23249.