CVE-2025-23249
CVSS 3.1 Score 7.6 of 10 (high)
Details
Published Apr 22, 2025
Updated: Apr 23, 2025
CWE ID 502
Summary
CVE-2025-23249 is a deserialization vulnerability affecting NVIDIA NeMo Framework. This issue enables a remote user to execute arbitrary code, potentially leading to serious consequences such as code execution and data tampering. The vulnerability arises due to insufficient input validation in the framework's deserialization process. Users are urged to apply the necessary patches to mitigate this risk and protect their systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.