CVE-2024-0104

NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and escalation of privileges.
References
Configurations

Configuration 1 (hide)

cpe:2.3:o:nvidia:onyx:*:*:*:*:lts:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:-:*:*:*
OR cpe:2.3:h:nvidia:tq8100-hs2f:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:tq8200-hs2f:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:nvidia:mlnx-gw:*:*:*:*:-:*:*:*
cpe:2.3:h:nvidia:mga100-hs2:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:nvidia:nvda-os_xc:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:mtq8400-hs2r:-:*:*:*:*:*:*:*

Configuration 5 (hide)

cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:-:*:*:*

History

26 Dec 2024, 19:44

Type Values Removed Values Added
CPE cpe:2.3:h:nvidia:skyway:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:metrox-3_xc:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:lts:*:*:*
cpe:2.3:h:nvidia:metrox-2:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:mtq8400-hs2r:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:mga100-hs2:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:tq8100-hs2f:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:tq8200-hs2f:-:*:*:*:*:*:*:*
First Time Nvidia mga100-hs2
Nvidia tq8200-hs2f
Nvidia tq8100-hs2f
Nvidia mtq8400-hs2r

Information

Published : 2024-08-08 18:15

Updated : 2024-12-26 19:44


NVD link : CVE-2024-0104

Mitre link : CVE-2024-0104

CVE.ORG link : CVE-2024-0104


JSON object : View

Products Affected

nvidia

  • onyx
  • nvda-os_xc
  • mtq8400-hs2r
  • mlnx-os
  • tq8100-hs2f
  • mlnx-gw
  • mga100-hs2
  • tq8200-hs2f
CWE
CWE-284

Improper Access Control

NVD-CWE-Other