PT-2025-2461 · Intel · Intel Neural Compressor

Published

2025-01-16

·

Updated

2025-01-18

·

CVE-2024-37181

CVSS v3.1

2.6

Low

VectorAV:A/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Intel(R) Neural Compressor versions prior to v3.0
Description: A time-of-check time-of-use race condition in the software may allow an authenticated user to potentially enable information disclosure via adjacent access.
Recommendations: For versions prior to v3.0, update to version v3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information and implementing additional security measures to minimize the risk of exploitation.

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-37181

Affected Products

Intel Neural Compressor