CVE-2025-33240: Code Injection
NVIDIA Megatron Bridge contains a vulnerability in a data shuffling tutorial, where malicious input could cause a code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33240?
CVE-2025-33240 is considered a high-severity vulnerability due to its potential for code execution and privilege escalation.
How do I fix CVE-2025-33240?
To fix CVE-2025-33240, update the Nvidia Megatron Bridge to the latest version beyond 0.2.2.
What could be the impact of exploiting CVE-2025-33240?
Exploiting CVE-2025-33240 could lead to code execution, privilege escalation, information disclosure, and data tampering.
Is CVE-2025-33240 exploitable remotely?
Yes, CVE-2025-33240 can be exploited remotely if the vulnerable software is exposed to untrusted input.
What versions of Nvidia Megatron Bridge are affected by CVE-2025-33240?
Nvidia Megatron Bridge versions up to and including 0.2.2 are affected by CVE-2025-33240.