CVE-2024-0113: NVIDIA Mlnx-Gw
High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.
NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI. A successful exploit of this vulnerability might lead to escalation of privileges and information disclosure.
Affected products
- NVIDIA Mlnx-Gw: before 8.1.4500 (fixed in 8.1.4500); before 8.2.2300 (fixed in 8.2.2300)
- NVIDIA Mlnx-OS: before 3.10.4500 (fixed in 3.10.4500); before 3.12.1002 (fixed in 3.12.1002); from 3.11.0000, before 3.11.2302 (fixed in 3.11.2302)
- NVIDIA Nvda-OS Xc: before 18.2.2200 (fixed in 18.2.2200)
- NVIDIA Onyx: before 3.10.4504 (fixed in 3.10.4504)
Published 2024-08-12. Last modified 2026-06-17.