CVE-2024-0104 is a high-severity vulnerability affecting the LDAP AAA component in various NVIDIA Mellanox products, including OS, ONYX, Skyway, MetroX-2, and MetroX-3 XC. A low-privileged attacker can exploit this network-based flaw with low complexity, potentially leading to information disclosure, data tampering, and privilege escalation. While no public exploit code or active exploitation has been observed, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.10.4402CPE matchmatch criteria | cpe:2.3:o:nvidia:onyx:*:*:*:*:lts:*:*:* | ||
< 3.11.2002CPE matchmatch criteria | cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:-:*:*:* | ||
< 8.2.2000CPE matchmatch criteria | cpe:2.3:o:nvidia:mlnx-gw:*:*:*:*:-:*:*:* | ||
< 18.2.2000CPE matchmatch criteria | cpe:2.3:o:nvidia:nvda-os_xc:*:*:*:*:*:*:*:* | ||
< 3.11.2202CPE matchmatch criteria | cpe:2.3:o:nvidia:mlnx-os:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.