cbcvebase.
CVE-2024-0113
published 2024-08-12

CVE-2024-0113: NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially…

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI. A successful exploit of this vulnerability might lead to escalation of privileges and information disclosure.

Affected

14 ranges
VendorProductVersion rangeFixed in
nvidiamellanox_os
nvidiamellanox_os
nvidiamellanox_os
nvidiametrox-2
nvidiametrox-3_xc
nvidiamlnx-gw< 8.1.45008.1.4500
nvidiamlnx-gw< 8.2.23008.2.2300
nvidiamlnx-os< 3.10.45003.10.4500
nvidiamlnx-os< 3.12.10023.12.1002
nvidiamlnx-os>= 3.11.0000 < 3.11.23023.11.2302
nvidianvda-os_xc< 18.2.220018.2.2200
nvidiaonyx< 3.10.45043.10.4504
nvidiaskyway
nvidiaskyway