Логотип exploitDog
bind:CVE-2023-25661
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-25661

Количество 4

Количество 4

nvd логотип

CVE-2023-25661

почти 3 года назад

TensorFlow is an Open Source Machine Learning Framework. In versions prior to 2.11.1 a malicious invalid input crashes a tensorflow model (Check Failed) and can be used to trigger a denial of service attack. A proof of concept can be constructed with the `Convolution3DTranspose` function. This Convolution3DTranspose layer is a very common API in modern neural networks. The ML models containing such vulnerable components could be deployed in ML applications or as cloud services. This failure could be potentially used to trigger a denial of service attack on ML cloud services. An attacker must have privilege to provide input to a `Convolution3DTranspose` call. This issue has been patched and users are advised to upgrade to version 2.11.1. There are no known workarounds for this vulnerability.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2023-25661

больше 2 лет назад

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-25661

почти 3 года назад

TensorFlow is an Open Source Machine Learning Framework. In versions p ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-fxgc-95xx-grvq

почти 3 года назад

TensorFlow Denial of Service vulnerability

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-25661

TensorFlow is an Open Source Machine Learning Framework. In versions prior to 2.11.1 a malicious invalid input crashes a tensorflow model (Check Failed) and can be used to trigger a denial of service attack. A proof of concept can be constructed with the `Convolution3DTranspose` function. This Convolution3DTranspose layer is a very common API in modern neural networks. The ML models containing such vulnerable components could be deployed in ML applications or as cloud services. This failure could be potentially used to trigger a denial of service attack on ML cloud services. An attacker must have privilege to provide input to a `Convolution3DTranspose` call. This issue has been patched and users are advised to upgrade to version 2.11.1. There are no known workarounds for this vulnerability.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
msrc логотип
CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-25661

TensorFlow is an Open Source Machine Learning Framework. In versions p ...

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-fxgc-95xx-grvq

TensorFlow Denial of Service vulnerability

CVSS3: 6.5
0%
Низкий
почти 3 года назад

Уязвимостей на страницу