CVE-2024-0104

NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and escalation of privileges.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:-:*:*:*
cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:lts:*:*:*
cpe:2.3:h:nvidia:metrox-2:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:nvidia:mlnx-gw:*:*:*:*:-:*:*:*
cpe:2.3:h:nvidia:skyway:-:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:nvidia:onyx:*:*:*:*:lts:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:nvidia:nvda-os_xc:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:metrox-3_xc:-:*:*:*:*:*:*:*

History

11 Sep 2024, 17:40

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.2
v2 : unknown
v3 : 8.8
First Time Nvidia
Nvidia mlnx-gw
Nvidia nvda-os Xc
Nvidia onyx
Nvidia metrox-2
Nvidia skyway
Nvidia mlnx-os
Nvidia metrox-3 Xc
CPE cpe:2.3:h:nvidia:metrox-3_xc:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:nvda-os_xc:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:skyway:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:mlnx-gw:*:*:*:*:-:*:*:*
cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:-:*:*:*
cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:lts:*:*:*
cpe:2.3:o:nvidia:onyx:*:*:*:*:lts:*:*:*
cpe:2.3:h:nvidia:metrox-2:-:*:*:*:*:*:*:*
Summary
  • (es) NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 y MetroX-3 XC contienen una vulnerabilidad en el componente LDAP AAA, donde un usuario puede provocar un acceso inadecuado. Una explotación exitosa de esta vulnerabilidad podría conducir a la divulgación de información, la manipulación de datos y la escalada de privilegios.
References () https://nvidia.custhelp.com/app/answers/detail/a_id/5559 - () https://nvidia.custhelp.com/app/answers/detail/a_id/5559 - Vendor Advisory
CWE NVD-CWE-Other

08 Aug 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-08 18:15

Updated : 2024-09-11 17:40


NVD link : CVE-2024-0104

Mitre link : CVE-2024-0104

CVE.ORG link : CVE-2024-0104


JSON object : View

Products Affected

nvidia

  • mlnx-os
  • skyway
  • metrox-2
  • nvda-os_xc
  • mlnx-gw
  • onyx
  • metrox-3_xc
CWE
NVD-CWE-Other CWE-284

Improper Access Control