CVE-2024-0106 is a vulnerability in NVIDIA ConnectX Host Firmware for BlueField DPUs, stemming from improper handling of insufficient privileges. This flaw carries a high CVSS score of 8.7, indicating a significant risk of denial of service, data tampering, and limited information disclosure, with a local attack vector and low complexity. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| NVIDIA | BlueField GA | All versions prior to xx.41.1000CNA affecteddefault unaffected | |
| NVIDIA | BlueField LTS23 | All versions prior to xx.39.3560CNA affecteddefault unaffected | |
| NVIDIA | BlueField LTS22 | All versions prior to xx.35.4030CNA affecteddefault unaffected | |
| NVIDIA | BlueField 1 | All versions prior to 18.31.1014CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.