GPU VulnDB

Database/Control plane, storage & DevOps

Intel Distribution of OpenVINO Model Server: An unauthenticated user can reach an input-validation flaw in OpenVINO

CVE-2024-32048Control plane, storage & DevOpscurated

Impact

An unauthenticated user can reach an input-validation flaw in OpenVINO Model Server. Model Server is a production inference endpoint, so this is on the request path of a live service.

Who can reach it

Anything that can send a request to the model server - which for most deployments is the whole cluster network, and sometimes the internet.

What to do

Upgrade OpenVINO Model Server to 2024.0 or later. Container image swap and rolling restart; no node reboot or firmware.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.