CVE-2025-33178: Code Injection
NVIDIA NeMo Framework for all platforms contains a vulnerability in the bert services component where malicious data created by an attacker may cause a code injection. A successful exploit of this vulnerability may lead to Code execution, Escalation of privileges, Information disclosure, and Data tampering.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33178?
CVE-2025-33178 has a high severity rating due to the potential for code execution and privilege escalation.
How do I fix CVE-2025-33178?
To fix CVE-2025-33178, ensure that you update the NVIDIA NeMo Framework to the latest version that addresses this vulnerability.
What are the potential impacts of CVE-2025-33178?
The potential impacts of CVE-2025-33178 include code execution, escalation of privileges, information disclosure, and data tampering.
Who is affected by CVE-2025-33178?
CVE-2025-33178 affects users of the NVIDIA NeMo Framework across all platforms.
Is CVE-2025-33178 exploitable remotely?
Yes, CVE-2025-33178 is exploitable remotely if an attacker can send malicious data to the bert services component.