CVE-2024-0113

EUVD-2024-15914
NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI. A successful exploit of this vulnerability might lead to escalation of privileges and information disclosure.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
Affected Products (NVD)
VendorProductVersion
nvidiamlnx-os
𝑥
< 3.10.4500
nvidiamlnx-os
𝑥
< 3.12.1002
nvidiamlnx-os
3.11.0000 ≤
𝑥
< 3.11.2302
nvidiaonyx
𝑥
< 3.10.4504
nvidiamlnx-gw
𝑥
< 8.1.4500
nvidiamlnx-gw
𝑥
< 8.2.2300
nvidianvda-os_xc
𝑥
< 18.2.2200
nvidiamlnx-os
𝑥
< 3.12.1002
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
nvidiamellanox_os_firmware
𝑥
≤ 3.11.4000
ADP
nvidiamellanox_os_firmware
𝑥
≤ 3.11.2200
ADP
nvidiamellanox_os_firmware
𝑥
≤ 3.10.4400
ADP
nvidiaskyway_firmware
𝑥
≤ 8.2.2200
ADP
nvidiaskyway_firmware
𝑥
≤ 8.1.4400
ADP
nvidiametrox-2_firmware
𝑥
≤ 3.11.4000
ADP
nvidiametrox-3_xc_firmware
𝑥
≤ 18.2.2200
ADP