Database/Control plane, storage & DevOps
Intel Neural Compressor: An unauthenticated user can reach an input-validation failure in Neural Compressor
Impact
An unauthenticated user can reach an input-validation failure in Neural Compressor and escalate. This is scored at the top of the scale, and Neural Compressor is a quantisation and optimisation service that teams commonly stand up as a shared internal endpoint next to their model registry - so an exposed instance is a pre-auth foothold beside your model weights.
Who can reach it
Network-reachable and unauthenticated where the service is exposed. Treat any internal deployment as reachable by anything else on the cluster network.
What to do
Upgrade Intel Neural Compressor to 2.5.0 or later immediately, and put the service behind authentication and network policy regardless of version. Python package update, restart the service - no node reboot or firmware.
References
Related entries
- Intel Neural Compressor: Unauthenticated input-validation failure leading to escalation of privilege in NeuralCVE-2024-28028 · Intel Neural CompressorHigh
- Intel Neural Compressor: Input-validation failure reachable by an authenticated user, ending in privilege escalationCVE-2024-36284 · Intel Neural CompressorMedium
- Palo Alto PAN-OS: GlobalProtect arbitrary file creationCVE-2024-3400 · Palo Alto PAN-OSCritical
- GitLab (ruby-saml): Ruby-SAML does not properly verify the SAML Response signatureCVE-2024-45409 · GitLab (ruby-saml)Critical
- Gitea: Stored cross-site scripting in Gitea 1.22.0CVE-2024-6886 · GiteaCritical
- Progress Kemp LoadMaster (including Multi-Tenancy edition): A request handler fails to validate its input beforeCVE-2024-7591 · Progress Kemp LoadMaster (including Multi-Tenancy edition)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.