NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI. A successful exploit of this vulnerability might lead to escalation of privileges and information disclosure.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://nvidia.custhelp.com/app/answers/detail/a_id/5563 |
History
Wed, 11 Sep 2024 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Nvidia mellanox Os
Nvidia metrox-2 Nvidia metrox-3 Xc Nvidia onyx Nvidia skyway |
|
Weaknesses | CWE-22 | |
CPEs | cpe:2.3:h:nvidia:metrox-2:*:*:*:*:*:metrox:*:* cpe:2.3:h:nvidia:metrox-3_xc:*:*:*:*:*:metrox:*:* cpe:2.3:h:nvidia:skyway:*:*:*:*:*:skyway:*:* cpe:2.3:h:nvidia:skyway:*:*:*:*:*:skyway_lts:*:* cpe:2.3:o:nvidia:mellanox_os:*:*:*:*:*:mellanox_os:*:* cpe:2.3:o:nvidia:mellanox_os:*:*:*:*:*:mellanox_os_lts:*:* cpe:2.3:o:nvidia:onyx:*:*:*:*:onyx_lts:*:*:* |
|
Vendors & Products |
Nvidia mellanox Os
Nvidia metrox-2 Nvidia metrox-3 Xc Nvidia onyx Nvidia skyway |
Tue, 13 Aug 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Nvidia
Nvidia mellanox Os Firmware Nvidia metrox-2 Firmware Nvidia metrox-3 Xc Firmware Nvidia skyway Firmware |
|
CPEs | cpe:2.3:o:nvidia:mellanox_os_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:nvidia:metrox-2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:nvidia:metrox-3_xc_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:nvidia:skyway_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Nvidia
Nvidia mellanox Os Firmware Nvidia metrox-2 Firmware Nvidia metrox-3 Xc Firmware Nvidia skyway Firmware |
|
Metrics |
ssvc
|
Fri, 09 Aug 2024 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI. A successful exploit of this vulnerability might lead to escalation of privileges and information disclosure. | |
Weaknesses | CWE-35 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: nvidia
Published: 2024-08-09T02:19:30.529Z
Updated: 2024-08-13T14:15:20.160Z
Reserved: 2023-12-02T00:42:23.928Z
Link: CVE-2024-0113
Vulnrichment
Updated: 2024-08-13T14:15:12.926Z
NVD
Status : Analyzed
Published: 2024-08-12T13:38:12.693
Modified: 2024-09-11T17:34:37.667
Link: CVE-2024-0113
Redhat
No data.