CVE-2024-0138: NVIDIA Base Command Manager

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

NVIDIA Base Command Manager contains a missing authentication vulnerability in the CMDaemon component. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

Affected products

  • NVIDIA Base Command Manager: version 10.24.09 only; from 10.24.09, before 10.24.09a (fixed in 10.24.09a)

Published 2024-11-23. Last modified 2026-06-17.