Threat Advisory

NVIDIA Triton Server Flaw Let Attackers Execute Remote Code

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Two critical vulnerabilities, identified as CVE-2024-0087 and CVE-2024-0088, have been discovered in NVIDIA’s Triton Inference Server, widely used for AI inference tasks. CVE-2024-0087 allows attackers to perform arbitrary file writes via the /v2/logging endpoint, potentially enabling remote code execution by injecting malicious scripts into system files. Meanwhile, CVE-2024-0088 arises from inadequate parameter validation in shared memory handling, facilitating arbitrary address writing and leading to potential data leakage or server instability through segmentation faults. Exploitation of these vulnerabilities could result in unauthorized access, data theft, or manipulation of AI model outcomes, posing serious risks to organizational security and user privacy. Immediate action is recommended for organizations relying on Triton Server to apply patches and bolster security measures to mitigate these threats effectively.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Two critical vulnerabilities, identified as CVE-2024-0087 and CVE-2024-0088, have been discovered in NVIDIA’s Triton Inference Server, widely used for AI inference tasks. CVE-2024-0087 allows attackers to perform arbitrary file writes via the /v2/logging endpoint, potentially enabling remote code execution by injecting malicious scripts into system files. Meanwhile, CVE-2024-0088 arises from inadequate parameter validation in shared memory handling, facilitating arbitrary address writing and leading to potential data leakage or server instability through segmentation faults. Exploitation of these vulnerabilities could result in unauthorized access, data theft, or manipulation of AI model outcomes, posing serious risks to organizational security and user privacy. Immediate action is recommended for organizations relying on Triton Server to apply patches and bolster security measures to mitigate these threats effectively.[emaillocker id="1283"]

RECOMMENDATION:

  • We strongly recommend you update NVIDIA Triton Inference Server to version 24.05.

REFERENCES:

The following reports contain further technical details:

https://cybersecuritynews.com/nvidia-triton-server-flaw/

[/emaillocker]
crossmenu