CVE-2024-0130: NVIDIA Ufm Cyberai Ga

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

NVIDIA UFM Enterprise, UFM Appliance, and UFM CyberAI contain a vulnerability where an attacker can cause an improper authentication issue by sending a malformed request through the Ethernet management interface. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and information disclosure.

Affected products

  • NVIDIA Ufm Cyberai Ga
  • NVIDIA Ufm Cyberai LTS23: version 2.6.1-3 LTS only
  • NVIDIA Ufm Enterprise Appliance Ga
  • NVIDIA Ufm Enterprise Appliance LTS23
  • NVIDIA Ufm Enterprise Ga
  • NVIDIA Ufm Enterprise LTS23
  • NVIDIA Ufm Sdn Appliance Ga
  • NVIDIA Ufm Sdn Appliance LTS23

Published 2024-12-06. Last modified 2026-06-17.