CVE-2024-0104

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
08/08/2024
Last modified:
26/12/2024

Description

NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and escalation of privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:nvidia:onyx:*:*:*:*:lts:*:*:* 3.10.4402 (excluding)
cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:-:*:*:* 3.11.2002 (excluding)
cpe:2.3:h:nvidia:tq8100-hs2f:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:tq8200-hs2f:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:mlnx-gw:*:*:*:*:-:*:*:* 8.2.2000 (excluding)
cpe:2.3:h:nvidia:mga100-hs2:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:nvda-os_xc:*:*:*:*:*:*:*:* 18.2.2000 (excluding)
cpe:2.3:h:nvidia:mtq8400-hs2r:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:-:*:*:* 3.11.2202 (excluding)


References to Advisories, Solutions, and Tools