CVE-2024-0113Path Traversal: '.../...//' in Nvidia Mlnx-gw

Severity
8.8HIGHNVD
CNA7.5
EPSS
0.3%
top 46.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12

Description

NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI. A successful exploit of this vulnerability might lead to escalation of privileges and information disclosure.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages8 packages

NVDnvidia/onyx< 3.10.4504
CVEListV5nvidia/skywayAll versions prior to and including 8.1.4400, All versions prior to and including 8.2.2200+1
CVEListV5nvidia/metrox-2All versions prior to and including 3.11.4000
CVEListV5nvidia/mellanox_osAll versions prior to and including 3.10.4400, All versions prior to and including 3.11.2200, All versions prior to and including 3.11.4000+2
CVEListV5nvidia/metrox-3_xcAll versions prior to and including 18.2.2200

🔴Vulnerability Details

2
GHSA
GHSA-vqxv-47fr-xm3x: NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a s2024-08-12
CVEList
CVE-2024-0113: NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a s2024-08-09
CVE-2024-0113 — Path Traversal: '.../...//' in Nvidia | cvebase