VDB
CVE-2025-2149
CVE-2025-2149
PUBLISHED
CVSS 2 LOW
A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. The manipulation of the argument scale/zero_point leads to improper initialization. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
EPSS 0.25% · 14.9th percentile
Risk Scores
CVSS 4.0
2
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score
0.25%
14.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | pytorch | 2.6.0 |
| Bitnami | pytorch | 2.6.0 |
Timeline
- Mar 10, 2025 CVE Published
- Mar 11, 2025 EPSS Score
- Mar 18, 2025 Coalition ESS Score
- Mar 25, 2025 EPSS Score
- Apr 8, 2025 EPSS Score
- Apr 22, 2025 EPSS Score
- May 6, 2025 EPSS Score
- May 20, 2025 EPSS Score
- Jun 3, 2025 EPSS Score
- Jun 17, 2025 EPSS Score
- Jun 23, 2025 Coalition ESS Score
- Jun 30, 2025 EPSS Score