CVE-2024-0113
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/08/2024
Last modified:
26/12/2024
Description
NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI. A successful exploit of this vulnerability might lead to escalation of privileges and information disclosure.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:lts:*:*:* | 3.10.4500 (excluding) | |
| cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:-:*:*:* | 3.12.1002 (excluding) | |
| cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:lts:*:*:* | 3.11.0000 (including) | 3.11.2302 (excluding) |
| cpe:2.3:o:nvidia:onyx:*:*:*:*:lts:*:*:* | 3.10.4504 (excluding) | |
| cpe:2.3:o:nvidia:mlnx-gw:*:*:*:*:lts:*:*:* | 8.1.4500 (excluding) | |
| cpe:2.3:o:nvidia:mlnx-gw:*:*:*:*:-:*:*:* | 8.2.2300 (excluding) | |
| cpe:2.3:h:nvidia:mga100-hs2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:nvidia:nvda-os_xc:*:*:*:*:*:*:*:* | 18.2.2200 (excluding) | |
| cpe:2.3:h:nvidia:mtq8400-hs2r:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:-:*:*:* | 3.12.1002 (excluding) | |
| cpe:2.3:h:nvidia:tq8100-hs2f:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:nvidia:tq8200-hs2f:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



