CVE-2025-33249: Command Injection
NVIDIA NeMo Framework for all platforms contains a vulnerability in a voice-preprocessing script, where malicious input created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33249?
CVE-2025-33249 is considered a high-severity vulnerability due to its potential for code execution and privilege escalation.
How do I fix CVE-2025-33249?
To fix CVE-2025-33249, update the NVIDIA NeMo Framework to the latest version that addresses the vulnerability.
What type of attack is associated with CVE-2025-33249?
CVE-2025-33249 is associated with code injection attacks through malicious input in a voice-preprocessing script.
What are the potential impacts of exploiting CVE-2025-33249?
Exploiting CVE-2025-33249 may lead to code execution, privilege escalation, or information disclosure.
Which software is affected by CVE-2025-33249?
CVE-2025-33249 affects the NVIDIA NeMo Framework across all supported platforms.