CVE-2025-33246

7.8

NVIDIA · NeMo Framework

A command injection vulnerability in the NVIDIA NeMo Framework ASR Evaluator utility allows local users to execute arbitrary code via crafted input in a configuration parameter.

Executive summary

A critical command injection vulnerability in the NVIDIA NeMo Framework could allow an authenticated local attacker to achieve full system compromise.

Vulnerability

The vulnerability exists within the ASR Evaluator utility due to improper neutralization of special elements used in a command (CWE-77). By supplying malicious input to a configuration parameter, a local user with low privileges can trigger command injection, leading to unauthorized code execution.

Business impact

The potential for unauthorized code execution poses a severe risk to the integrity and availability of the affected system. Given the CVSS score of 7.8, this vulnerability allows for privilege escalation, data tampering, and potential information disclosure, which could lead to significant operational disruption or the compromise of sensitive model data within the development environment.

Remediation

Immediate Action: Update the NVIDIA NeMo Framework to version 2.6.1 or later to resolve the underlying command injection flaw.

Proactive Monitoring: Review system logs for unusual process execution patterns or unexpected command-line arguments originating from the ASR Evaluator utility.

Compensating Controls: Restrict local access to the server hosting the NeMo Framework to only essential personnel and utilize endpoint detection and response tools to monitor for unauthorized shell commands.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this command injection vulnerability necessitates immediate attention. Administrators must prioritize updating the NVIDIA NeMo Framework to version 2.6.1 to eliminate the risk of arbitrary code execution. Failure to patch the system leaves the infrastructure vulnerable to local privilege escalation and subsequent compromise of critical AI research assets.

More NVIDIA CVEs

Sources