PT-2024-10339 · Aim · Aim

Published

2024-10-20

·

Updated

2025-07-18

·

CVE-2024-12778

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Aim (affected versions not specified)
Description The issue is related to the web interface of the Aim machine learning experiment tracking and logging software, where an uncontrolled resource consumption can cause a server lockup during processing. This can be exploited by a remote attacker to cause a denial of service by sending a specially crafted request.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2025-00819
CVE-2024-12778
GHSA-35P3-6J45-PRWM

Affected Products

Aim