← Back

CVE-2024-0113

nvd nist
Published: Aug 12, 2024Modified: Dec 26, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI. A successful exploit of this vulnerability might lead to escalation of privileges and information disclosure.

Affected (7)

4 products
Mlnx Os
Onyx
Mlnx Gw
Nvda Os Xc
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Nvidia
Before 3.10.4500
From 3.11.0000 to 3.11.2302
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.10.4504
Configuration C
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Nvidia
Before 8.2.2300
Before 8.1.4500
Running on/withPlatform Versions
Nvidia
Mga100 Hs2
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 18.2.2200
Running on/withPlatform Versions
Nvidia
Mtq8400 Hs2r
All versions
Configuration E
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Before 3.12.1002
Running on/withPlatform Versions
Nvidia
Tq8100 Hs2f
All versions
Nvidia
Tq8200 Hs2f
All versions

References (1)

Source: psirt@nvidia.com
Vendor Advisory

Timeline

No history available yet.