First published: Thu Aug 08 2024(Updated: )
NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and escalation of privileges.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA Onyx | <3.10.4402 | |
All of | ||
Nvidia Mlnx-os | <3.11.2002 | |
Any of | ||
Nvidia Tq8100-hs2f | ||
Nvidia Tq8200-hs2f | ||
All of | ||
Nvidia Mlnx-gw | <8.2.2000 | |
Nvidia Mga100-hs2 | ||
All of | ||
Nvidia Nvda-os Xc | <18.2.2000 | |
Nvidia Mtq8400-hs2r | ||
Nvidia Mlnx-os | <3.11.2202 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0104 has been classified with a high severity due to the potential for information disclosure and privilege escalation.
To fix CVE-2024-0104, update the affected software to the latest available version provided by NVIDIA.
The products impacted by CVE-2024-0104 include NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2, and MetroX-3 XC versions below the specified limits.
Exploiting CVE-2024-0104 can lead to information disclosure, data tampering, and escalation of privileges.
Currently, the recommended approach for CVE-2024-0104 is to apply the latest updates as no specific workaround is documented.