Database/Control plane, storage & DevOps
Intel Distribution of OpenVINO Model Server: An unauthenticated user can reach an input-validation flaw in OpenVINO
CVE-2024-32048Control plane, storage & DevOpscurated
Impact
An unauthenticated user can reach an input-validation flaw in OpenVINO Model Server. Model Server is a production inference endpoint, so this is on the request path of a live service.
Who can reach it
Anything that can send a request to the model server - which for most deployments is the whole cluster network, and sometimes the internet.
What to do
Upgrade OpenVINO Model Server to 2024.0 or later. Container image swap and rolling restart; no node reboot or firmware.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.