CVE-2024-0104

NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and escalation of privileges.
References
Configurations

Configuration 1 (hide)

cpe:2.3:o:nvidia:onyx:*:*:*:*:lts:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:-:*:*:*
OR cpe:2.3:h:nvidia:tq8100-hs2f:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:tq8200-hs2f:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:nvidia:mlnx-gw:*:*:*:*:-:*:*:*
cpe:2.3:h:nvidia:mga100-hs2:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:nvidia:nvda-os_xc:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:mtq8400-hs2r:-:*:*:*:*:*:*:*

Configuration 5 (hide)

cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:-:*:*:*

History

26 Dec 2024, 19:44

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 4.2
First Time Nvidia mga100-hs2
Nvidia tq8100-hs2f
Nvidia tq8200-hs2f
Nvidia mtq8400-hs2r
CPE cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:lts:*:*:*
cpe:2.3:h:nvidia:skyway:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:metrox-3_xc:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:metrox-2:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:tq8200-hs2f:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:tq8100-hs2f:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:mga100-hs2:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:mtq8400-hs2r:-:*:*:*:*:*:*:*

11 Sep 2024, 17:40

Type Values Removed Values Added
CWE NVD-CWE-Other
CVSS v2 : unknown
v3 : 4.2
v2 : unknown
v3 : 8.8
First Time Nvidia
Nvidia mlnx-gw
Nvidia nvda-os Xc
Nvidia onyx
Nvidia metrox-2
Nvidia skyway
Nvidia mlnx-os
Nvidia metrox-3 Xc
CPE cpe:2.3:h:nvidia:metrox-3_xc:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:nvda-os_xc:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:skyway:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:mlnx-gw:*:*:*:*:-:*:*:*
cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:-:*:*:*
cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:lts:*:*:*
cpe:2.3:o:nvidia:onyx:*:*:*:*:lts:*:*:*
cpe:2.3:h:nvidia:metrox-2:-:*:*:*:*:*:*:*
Summary
  • (es) NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 y MetroX-3 XC contienen una vulnerabilidad en el componente LDAP AAA, donde un usuario puede provocar un acceso inadecuado. Una explotación exitosa de esta vulnerabilidad podría conducir a la divulgación de información, la manipulación de datos y la escalada de privilegios.
References () https://nvidia.custhelp.com/app/answers/detail/a_id/5559 - () https://nvidia.custhelp.com/app/answers/detail/a_id/5559 - Vendor Advisory

08 Aug 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-08 18:15

Updated : 2024-12-26 19:44


NVD link : CVE-2024-0104

Mitre link : CVE-2024-0104

CVE.ORG link : CVE-2024-0104


JSON object : View

Products Affected

nvidia

  • onyx
  • tq8200-hs2f
  • mga100-hs2
  • mlnx-os
  • tq8100-hs2f
  • nvda-os_xc
  • mtq8400-hs2r
  • mlnx-gw
CWE
CWE-284

Improper Access Control

NVD-CWE-Other