S0049RS3-T12-S0049-Z · Full risk code

Exploitation of Deep Learning Framework Vulnerabilities

深度學習框架漏洞遭利用

Design & Development
Risk Description

When an organization's inference service runs a framework version with known vulnerabilities; due to unmitigated control gaps, an attacker exploits one to gain execution privileges and move laterally into the internal network, triggering external stakeholder impacts and causing the organization's patching process does not cover AI-related components, leaving the vulnerability unaddressed for an extended period.

Framework Mappings

OWASP Top 10 for LLMLLM03
MITRE ATLASAML.T0010
NIST CSF 2.0PR.PS、DE.CM
ISO/IEC 42001Annex A.10.3
ISO/IEC 5338設計與開發

Risk Treatment & Implementation Guidance

Include AI frameworks and inference components in vulnerability scanning and patch management; Segment inference services on the network to limit lateral movement after compromise; Automate scanning with patching deadlines for known vulnerabilities