CVE-2024-22476
Intel Neural Compressor <2.5.0 - SQL Injection
Record summary
CVE-2024-22476 has a selected CVSS score of 10.0 (critical); EIP currently links 1 Nuclei template.
Description
Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable escalation of privilege via remote access.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 20, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
neural_compressor_softwareBrowse intel / neural_compressor_softwareDefault status: unknown | CVE List | - to < 2.5.0 | affected |
Intel(R) Neural Compressor softwareDefault status: unaffected | CVE List | before version 2.5.0 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALIntel Neural Compressor <2.5.0 - SQL InjectionCVSS 10
Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable escalation of privilege via remote access.
Impact
Unauthenticated attackers can escalate privileges or perform malicious actions through improper input validation in Intel Neural Compressor.
Remediation
Update Intel Neural Compressor to version 2.5.0 or later.
Source: ProjectDiscovery