漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
NVIDIA SIL GEN3C Unauthenticated RCE via Pickle Deserialization in Inference API
Vulnerability Description
NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's pickle.loads() without authentication or input validation. Attackers can supply a crafted payload containing a __reduce__ gadget to the inference API port to achieve remote code execution as the inference process.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
可信数据的反序列化
Vulnerability Title
NVIDIA Spatial Intelligence Lab GEN3C 反序列化注入漏洞
Vulnerability Description
NVIDIA Spatial Intelligence Lab GEN3C是美国NVIDIA Spatial Intelligence Lab组织的一个三维生成模型框架。 NVIDIA Spatial Intelligence Lab GEN3C存在反序列化注入漏洞,该漏洞源于推理API服务器中的/request-inference和/seed-model端点使用Python的pickle.loads()反序列化原始HTTP请求主体,没有进行身份验证或输入验证,可能导致攻击者提供包含__reduce__小
CVSS Information
N/A
Vulnerability Type
N/A