CVE-2024-0113
HIGHDescription
NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI. A successful exploit of this vulnerability might lead to escalation of privileges and information disclosure.
Is your site exposed to CVE-2024-0113?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| nvidia | mlnx-os |
| nvidia | mlnx-os |
| nvidia | mlnx-os |
| nvidia | onyx |
| nvidia | mlnx-gw |
| nvidia | mlnx-gw |
| nvidia | mga100-hs2 |
| nvidia | nvda-os_xc |
| nvidia | mtq8400-hs2r |
| nvidia | mlnx-os |
| nvidia | tq8100-hs2f |
| nvidia | tq8200-hs2f |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-0113? +
How severe is CVE-2024-0113? +
What products are affected by CVE-2024-0113? +
How do I check if I'm vulnerable to CVE-2024-0113? +
Related Vulnerabilities
Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs rule …
A Path Traversal vulnerability in the tftpsync/add and tftpsync/delete scripts allows a remote attacker on an adjacent network to write …
DIAView (v4.2.0 and prior) - Directory Traversal Information Disclosure Vulnerability
`oak` is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. …
Path Traversal vulnerability in WF Steuerungstechnik GmbH airleader MASTER allows Retrieve Embedded Sensitive Data.This issue affects airleader MASTER: 3.0046.
Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_file.php endpoint used for …