CVE-2024-0140 MEDIUM

CVE-2024-0140

Vendor Nvidia
Product RAPIDS cuDF and cuML
Weakness CWE-502 · Unsafe deserialization
Published January 28, 2025
Last update January 28, 2025

CVSS base score

6.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H

What the vulnerability does

01Description

NVIDIA RAPIDS contains a vulnerability in cuDF and cuML, where a user could cause a deserialization of untrusted data issue. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.

Key dates

02Disclosure timeline

January 28, 2025 CVE published
January 28, 2025 Record updated