NVIDIA Mellanox OS Vulnerability Affects Security
CVE-2024-0104

8.8HIGH

Key Information:

Vendor
Nvidia
Vendor
CVE Published:
8 August 2024

Summary

A vulnerability in the LDAP Authentication, Authorization, and Accounting (AAA) component of NVIDIA's Mellanox OS, as well as the ONYX, Skyway, MetroX-2, and MetroX-3 XC products, allows for improper access due to user interactions. Exploitation of this vulnerability can result in serious consequences, including unauthorized access to sensitive information, potential data alterations, and the possibility of privilege escalation. Securing these environments is vital to preventing adverse security events.

Affected Version(s)

Mellanox OS Mellanox OS LTS All versions prior to and including 3.11.2100

MetroX-2 MetroX All versions prior to and including 3.11.1000

MetroX-3 XC MetroX All versions prior to and including 18.2.2100

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.