CVE-2023-52310

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 3, 2024
Updated: Jan 5, 2024
CWE ID 78

Summary

CVE-2023-52310 is a newly discovered vulnerability affecting PaddlePaddle versions prior to 2.6.0. This issue permits an attacker to inject commands into the get_online_pass_interval function, leading to arbitrary command execution on the operating system. Successful exploitation of this vulnerability could grant an attacker significant access and control over the affected system. Users are strongly encouraged to update to the latest version of PaddlePaddle to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share