Описание
NVIDIA Megatron-LM contains a vulnerability in the hybrid conversion script where an Attacker may cause an RCE by convincing a user to load a maliciously crafted file. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.
Ссылки
- Third Party AdvisoryUS Government Resource
- Vendor Advisory
- Third Party Advisory
Уязвимые конфигурации
EPSS
7.8 High
CVSS3
7.8 High
CVSS3
Дефекты
Связанные уязвимости
NVIDIA Megatron-LM contains a vulnerability in the hybrid conversion script where an Attacker may cause an RCE by convincing a user to load a maliciously crafted file. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.
Уязвимость сценария гибридного преобразования библиотеки для обучения больших языковых моделей NVIDIA Megatron-LM, позволяющая нарушителю выполнить произвольный код, повысить свои привилегии, получить несанкционированный доступ к защищаемой информации и осуществить подмену данных
EPSS
7.8 High
CVSS3
7.8 High
CVSS3