Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-15914 | NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI. A successful exploit of this vulnerability might lead to escalation of privileges and information disclosure. |
| Link | Providers |
|---|---|
| https://nvidia.custhelp.com/app/answers/detail/a_id/5563 |
|
Thu, 26 Dec 2024 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nvidia mga100-hs2
Nvidia mlnx-gw Nvidia mlnx-os Nvidia mtq8400-hs2r Nvidia nvda-os Xc Nvidia tq8100-hs2f Nvidia tq8200-hs2f |
|
| CPEs | cpe:2.3:h:nvidia:metrox-3_xc:*:*:*:*:*:metrox:*:* cpe:2.3:h:nvidia:skyway:*:*:*:*:*:skyway:*:* cpe:2.3:h:nvidia:skyway:*:*:*:*:*:skyway_lts:*:* cpe:2.3:o:nvidia:mellanox_os:*:*:*:*:*:mellanox_os:*:* cpe:2.3:o:nvidia:mellanox_os:*:*:*:*:*:mellanox_os_lts:*:* cpe:2.3:o:nvidia:onyx:*:*:*:*:onyx_lts:*:*:* |
cpe:2.3:h:nvidia:mga100-hs2:-:*:*:*:*:*:*:* cpe:2.3:h:nvidia:mtq8400-hs2r:-:*:*:*:*:*:*:* cpe:2.3:h:nvidia:tq8100-hs2f:-:*:*:*:*:*:*:* cpe:2.3:h:nvidia:tq8200-hs2f:-:*:*:*:*:*:*:* cpe:2.3:o:nvidia:mlnx-gw:*:*:*:*:-:*:*:* cpe:2.3:o:nvidia:mlnx-gw:*:*:*:*:lts:*:*:* cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:-:*:*:* cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:lts:*:*:* cpe:2.3:o:nvidia:nvda-os_xc:*:*:*:*:*:*:*:* cpe:2.3:o:nvidia:onyx:*:*:*:*:lts:*:*:* |
| Vendors & Products |
Nvidia mellanox Os
Nvidia metrox-2 Nvidia metrox-3 Xc Nvidia skyway |
Nvidia mga100-hs2
Nvidia mlnx-gw Nvidia mlnx-os Nvidia mtq8400-hs2r Nvidia nvda-os Xc Nvidia tq8100-hs2f Nvidia tq8200-hs2f |
Wed, 11 Sep 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nvidia mellanox Os
Nvidia metrox-2 Nvidia metrox-3 Xc Nvidia onyx Nvidia skyway |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:h:nvidia:metrox-2:*:*:*:*:*:metrox:*:* cpe:2.3:h:nvidia:metrox-3_xc:*:*:*:*:*:metrox:*:* cpe:2.3:h:nvidia:skyway:*:*:*:*:*:skyway:*:* cpe:2.3:h:nvidia:skyway:*:*:*:*:*:skyway_lts:*:* cpe:2.3:o:nvidia:mellanox_os:*:*:*:*:*:mellanox_os:*:* cpe:2.3:o:nvidia:mellanox_os:*:*:*:*:*:mellanox_os_lts:*:* cpe:2.3:o:nvidia:onyx:*:*:*:*:onyx_lts:*:*:* |
|
| Vendors & Products |
Nvidia mellanox Os
Nvidia metrox-2 Nvidia metrox-3 Xc Nvidia onyx Nvidia skyway |
Tue, 13 Aug 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nvidia
Nvidia mellanox Os Firmware Nvidia metrox-2 Firmware Nvidia metrox-3 Xc Firmware Nvidia skyway Firmware |
|
| CPEs | cpe:2.3:o:nvidia:mellanox_os_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:nvidia:metrox-2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:nvidia:metrox-3_xc_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:nvidia:skyway_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Nvidia
Nvidia mellanox Os Firmware Nvidia metrox-2 Firmware Nvidia metrox-3 Xc Firmware Nvidia skyway Firmware |
|
| Metrics |
ssvc
|
Fri, 09 Aug 2024 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI. A successful exploit of this vulnerability might lead to escalation of privileges and information disclosure. | |
| Weaknesses | CWE-35 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
Status: PUBLISHED
Assigner: nvidia
Published:
Updated: 2024-08-13T14:15:20.160Z
Reserved: 2023-12-02T00:42:23.928Z
Link: CVE-2024-0113
Updated: 2024-08-13T14:15:12.926Z
Status : Analyzed
Published: 2024-08-12T13:38:12.693
Modified: 2024-12-26T19:21:52.380
Link: CVE-2024-0113
No data.
OpenCVE Enrichment
No data.
EUVD