CVE-2025-33246: Command Injection
NVIDIA NeMo Framework for all platforms contains a vulnerability in the ASR Evaluator utility, where a user could cause a command injection by supplying crafted input to a configuration parameter. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, or information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33246?
CVE-2025-33246 is considered to have a high severity due to its potential for command injection, leading to code execution and privilege escalation.
How do I fix CVE-2025-33246?
To fix CVE-2025-33246, update the NVIDIA NeMo Framework to the latest version beyond 2.6.1 to mitigate the vulnerability.
What types of systems are affected by CVE-2025-33246?
CVE-2025-33246 affects all platforms that run the NVIDIA NeMo Framework, specifically versions up to and including 2.6.1.
What kind of exploit is possible with CVE-2025-33246?
An exploit of CVE-2025-33246 may allow an attacker to perform command injection, which can result in arbitrary code execution and elevated privileges.
Who is the vendor responsible for CVE-2025-33246?
The vendor responsible for CVE-2025-33246 is NVIDIA, which develops the NeMo Framework.