CVE-2024-0138: NVIDIA Base Command Manager
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
NVIDIA Base Command Manager contains a missing authentication vulnerability in the CMDaemon component. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Affected products
- NVIDIA Base Command Manager: version 10.24.09 only; from 10.24.09, before 10.24.09a (fixed in 10.24.09a)
Published 2024-11-23. Last modified 2026-06-17.