Security Advisory

CVE-2023-31036

7.5
HIGH

Vulnerability Description

NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where, when it is launched with the non-default command line option --model-control explicit, an attacker may use the model load API to cause a relative path traversal. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published Date January 12, 2024
Official Source NIST NVD Advisory