Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-11041

vllm-project vllm version v0.6.2 contains a vulnerability in the MessageQueue.dequeue() API function. The function uses pickle.loads to parse received sockets directly, leading to a remote code execution vulnerability. An attacker can exploit this by sending a malicious payload to the MessageQueue, causing the victim's machine to execute arbitrary code.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 65.3%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2024-11041
  • Vllm » Vllm » Version: 0.6.2
    cpe:2.3:a:vllm:vllm:0.6.2


Contact Us

Shodan ® - All rights reserved