Database/Control plane, storage & DevOps
Intel Distribution of OpenVINO Model Server: An unauthenticated user can reach an input-validation flaw in OpenVINO
CVSS 6.5CVE-2024-32048Control plane, storage & DevOpscurated
Impact
An unauthenticated user can reach an input-validation flaw in OpenVINO Model Server. Model Server is a production inference endpoint, so this is on the request path of a live service.
Who can reach it
Anything that can send a request to the model server - which for most deployments is the whole cluster network, and sometimes the internet.
What to do
Upgrade OpenVINO Model Server to 2024.0 or later. Container image swap and rolling restart; no node reboot or firmware.
References
Related entries
- GitLab EE: crafted SCIM provisioning input triggers an unbounded loop and takes the instance downCVE-2025-10903 · GitLab EE (SCIM user provisioning)Medium
- rpc.mountd: NFSv3 client bypasses export restrictions and root_squash on subdirectoriesCVE-2025-12801 · nfs-utils rpc.mountd (NFSv3 export subtree access)Medium
- OpenVINO Model Server: An unauthenticated request can drive OpenVINO Model Server into unbounded resource consumptionCVE-2025-22892 · OpenVINO Model ServerMedium
- IBM Storage Scale SMB protocol stack (inherited ACL handling): Files created or modified over SMB inherit permissionsCVE-2025-36104 · IBM Storage Scale SMB protocol stack (inherited ACL handling)Medium
- CephFS (ceph-fuse client): A tenant with an ordinary unprivileged UID on a node that has a CephFS volume mounted viaCVE-2025-52555 · CephFS (ceph-fuse client)Medium
- PostgreSQL pgcrypto: PGP functions emit recoverable cleartext when OpenSSL disables the cipherCVE-2026-14663 · PostgreSQL pgcrypto (pgp_sym_encrypt / pgp_pub_encrypt family)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.