Back to Database
Status published
Medium
CVE-2024-0129
NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user...
Vulnerability Description
NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe .tar file extraction. A successful exploit of this vulnerability may lead to code execution and data tampering.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-0129
Credits & Attribution
No credits recorded in the NVD database.
More from NVIDIA
View All →CVE-2025-33255
NVIDIA TRT-LLM for any platform contains a vulnerability in MPI...
High
7.5
CVE-2025-33254
NVIDIA Triton Inference Server contains a vulnerability where an attacker...
High
7.5
CVE-2025-33253
NVIDIA NeMo Framework contains a vulnerability where an attacker could...
High
7.8
CVE-2025-33252
NVIDIA NeMo Framework contains a vulnerability where an attacker could...
High
7.8
CVE-2025-33251
NVIDIA NeMo Framework contains a vulnerability where an attacker could...
High
7.8
Affected Vendor
NVIDIA
View all reports →Affected Software
NeMo
Vulnerable Versions:
All versions prior to r2.0.0rc0
Timeline
Official Publish:
October 15th, 2024
Last Modified:
October 15th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L