Resource exhaustion in OpenVINO Model Server software for Distribution of OpenVINO toolkit - CVE-2025-22892
Published: May 14, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker on the local network can send specially crafted traffic to he device, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Lenovo Intelligent Computing Orchestration (LiCO)
How to mitigate CVE-2025-22892
Lenovo Intelligent Computing Orchestration (LiCO) - update to 8.0