8.8

CVE-2024-0104

NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and escalation of privileges.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NvidiaOnyx SwEditionlts Version < 3.10.4402
NvidiaMlnx-os SwEdition- Version < 3.11.2002
   NvidiaTq8100-hs2f Version-
   NvidiaTq8200-hs2f Version-
NvidiaMlnx-gw SwEdition- Version < 8.2.2000
   NvidiaMga100-hs2 Version-
NvidiaNvda-os Xc Version < 18.2.2000
   NvidiaMtq8400-hs2r Version-
NvidiaMlnx-os SwEdition- Version < 3.11.2202
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.58
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
psirt@nvidia.com 4.2 1.6 2.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.