CVE-2024-0105 is a high-severity vulnerability in NVIDIA ConnectX Firmware, where improper handling of insufficient privileges allows an attacker to cause denial of service, data tampering, and limited information disclosure. With a CVSS score of 8.9, this vulnerability is network-adjacent, low complexity, and requires low privileges to exploit. Currently, there is no public exploit code available, it is not listed in CISA's KEV catalog, and there is minimal community discussion or media coverage surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| NVIDIA | BlueField GA | All versions prior to xx.41.1000CNA affecteddefault unaffected | |
| NVIDIA | BlueField LTS23 | All versions prior to xx.39.3560CNA affecteddefault unaffected | |
| NVIDIA | BlueField LTS22 | All versions prior to xx.35.4030CNA affecteddefault unaffected | |
| NVIDIA | ConnectX LTS22 | All versions prior to xx.35.4030CNA affecteddefault unaffected | |
| NVIDIA | ConnectX GA | All versions prior to xx.41.1000CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.