peter bassill · operator
$ cve CVE-2024-22476 JSON

CVE-2024-22476

10.0
CRITICAL · CVSS 3.1 · EPSS 36% (pctl 98)

Patch early

EPSS 36% — above the 10% action threshold.

Description

Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable escalation of privilege via remote access.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS35.97% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2024-05-16
Last modified2026-06-17

References

→ the Explorer  ·  watch your stack  ·  NVD