GPU VulnDB

Database/Control plane, storage & DevOps

Intel Neural Compressor: An unauthenticated user can reach an input-validation failure in Neural Compressor

CVE-2024-22476Control plane, storage & DevOpscurated

Impact

An unauthenticated user can reach an input-validation failure in Neural Compressor and escalate. This is scored at the top of the scale, and Neural Compressor is a quantisation and optimisation service that teams commonly stand up as a shared internal endpoint next to their model registry - so an exposed instance is a pre-auth foothold beside your model weights.

Who can reach it

Network-reachable and unauthenticated where the service is exposed. Treat any internal deployment as reachable by anything else on the cluster network.

What to do

Upgrade Intel Neural Compressor to 2.5.0 or later immediately, and put the service behind authentication and network policy regardless of version. Python package update, restart the service - no node reboot or firmware.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.