CVE-2025-23314: Code Injection
NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by an attacker could cause a code injection issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23314?
CVE-2025-23314 is classified as a high-severity vulnerability due to its potential for code execution and privilege escalation.
How do I fix CVE-2025-23314?
To fix CVE-2025-23314, update the NVIDIA NeMo Framework to the latest available version that addresses this vulnerability.
What are the potential impacts of exploiting CVE-2025-23314?
Exploiting CVE-2025-23314 may lead to code execution, escalation of privileges, and information disclosure.
Who is affected by CVE-2025-23314?
CVE-2025-23314 affects all platforms using the NVIDIA NeMo Framework.
Can CVE-2025-23314 be exploited remotely?
Yes, CVE-2025-23314 can potentially be exploited remotely if the attacker can provide malicious data to the NLP component.