5.3
CVE-2020-26266
- EPSS 0.05%
- Published 10.12.2020 23:15:12
- Last modified 21.11.2024 05:19:42
- Source security-advisories@github.com
- Teams watchlist Login
- Open Login
In affected versions of TensorFlow under certain cases a saved model can trigger use of uninitialized values during code execution. This is caused by having tensor buffers be filled with the default value of the type but forgetting to default initialize the quantized floating point types in Eigen. This is fixed in versions 1.15.5, 2.0.4, 2.1.3, 2.2.2, 2.3.2, and 2.4.0.
Data is provided by the National Vulnerability Database (NVD)
Google ≫ Tensorflow Version < 1.15.5
Google ≫ Tensorflow Version >= 2.0.0 < 2.0.4
Google ≫ Tensorflow Version >= 2.1.0 < 2.1.3
Google ≫ Tensorflow Version >= 2.2.0 < 2.2.2
Google ≫ Tensorflow Version >= 2.3.0 < 2.3.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.05% | 0.155 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.3 | 1.8 | 3.4 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
|
nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
security-advisories@github.com | 4.4 | 1.8 | 2.5 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
|
CWE-908 Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.