CVE-2024-0113

NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI. A successful exploit of this vulnerability might lead to escalation of privileges and information disclosure.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:lts:*:*:*
cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:-:*:*:*
cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:lts:*:*:*

Configuration 2 (hide)

cpe:2.3:o:nvidia:onyx:*:*:*:*:lts:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:nvidia:mlnx-gw:*:*:*:*:lts:*:*:*
cpe:2.3:o:nvidia:mlnx-gw:*:*:*:*:-:*:*:*
cpe:2.3:h:nvidia:mga100-hs2:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:nvidia:nvda-os_xc:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:mtq8400-hs2r:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:-:*:*:*
OR cpe:2.3:h:nvidia:tq8100-hs2f:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:tq8200-hs2f:-:*:*:*:*:*:*:*

History

26 Dec 2024, 19:21

Type Values Removed Values Added
First Time Nvidia tq8200-hs2f
Nvidia tq8100-hs2f
Nvidia mlnx-os
Nvidia mlnx-gw
Nvidia mga100-hs2
Nvidia mtq8400-hs2r
Nvidia nvda-os Xc
CPE cpe:2.3:h:nvidia:skyway:*:*:*:*:*:skyway_lts:*:*
cpe:2.3:h:nvidia:metrox-2:*:*:*:*:*:metrox:*:*
cpe:2.3:h:nvidia:skyway:*:*:*:*:*:skyway:*:*
cpe:2.3:h:nvidia:metrox-3_xc:*:*:*:*:*:metrox:*:*
cpe:2.3:o:nvidia:mellanox_os:*:*:*:*:*:mellanox_os_lts:*:*
cpe:2.3:o:nvidia:mellanox_os:*:*:*:*:*:mellanox_os:*:*
cpe:2.3:o:nvidia:onyx:*:*:*:*:onyx_lts:*:*:*
cpe:2.3:h:nvidia:mtq8400-hs2r:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:mlnx-gw:*:*:*:*:lts:*:*:*
cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:lts:*:*:*
cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:-:*:*:*
cpe:2.3:o:nvidia:mlnx-gw:*:*:*:*:-:*:*:*
cpe:2.3:o:nvidia:onyx:*:*:*:*:lts:*:*:*
cpe:2.3:h:nvidia:tq8200-hs2f:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:nvda-os_xc:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:mga100-hs2:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:tq8100-hs2f:-:*:*:*:*:*:*:*

Information

Published : 2024-08-12 13:38

Updated : 2024-12-26 19:21


NVD link : CVE-2024-0113

Mitre link : CVE-2024-0113

CVE.ORG link : CVE-2024-0113


JSON object : View

Products Affected

nvidia

  • onyx
  • nvda-os_xc
  • mtq8400-hs2r
  • mlnx-os
  • tq8100-hs2f
  • mlnx-gw
  • mga100-hs2
  • tq8200-hs2f
CWE
CWE-35

Path Traversal: '.../...//'

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')