NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and escalation of privileges.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-15905 NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and escalation of privileges.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 27 Dec 2024 05:00:00 +0900

Type Values Removed Values Added
First Time appeared Nvidia mga100-hs2
Nvidia mtq8400-hs2r
Nvidia tq8100-hs2f
Nvidia tq8200-hs2f
CPEs cpe:2.3:h:nvidia:metrox-2:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:metrox-3_xc:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:skyway:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:lts:*:*:*
cpe:2.3:h:nvidia:mga100-hs2:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:mtq8400-hs2r:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:tq8100-hs2f:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:tq8200-hs2f:-:*:*:*:*:*:*:*
Vendors & Products Nvidia metrox-2
Nvidia metrox-3 Xc
Nvidia skyway
Nvidia mga100-hs2
Nvidia mtq8400-hs2r
Nvidia tq8100-hs2f
Nvidia tq8200-hs2f

Thu, 12 Sep 2024 03:00:00 +0900

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia metrox-2
Nvidia metrox-3 Xc
Nvidia mlnx-gw
Nvidia mlnx-os
Nvidia nvda-os Xc
Nvidia onyx
Nvidia skyway
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:h:nvidia:metrox-2:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:metrox-3_xc:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:skyway:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:mlnx-gw:*:*:*:*:-:*:*:*
cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:-:*:*:*
cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:lts:*:*:*
cpe:2.3:o:nvidia:nvda-os_xc:*:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:onyx:*:*:*:*:lts:*:*:*
Vendors & Products Nvidia
Nvidia metrox-2
Nvidia metrox-3 Xc
Nvidia mlnx-gw
Nvidia mlnx-os
Nvidia nvda-os Xc
Nvidia onyx
Nvidia skyway

Fri, 09 Aug 2024 03:30:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 09 Aug 2024 02:30:00 +0900

Type Values Removed Values Added
Description NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and escalation of privileges.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2024-08-08T17:35:33.292Z

Reserved: 2023-12-02T00:42:14.023Z

Link: CVE-2024-0104

cve-icon Vulnrichment

Updated: 2024-08-08T17:35:26.967Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-08T18:15:09.800

Modified: 2024-12-26T19:44:22.577

Link: CVE-2024-0104

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses