CVE-2024-0113
NVIDIA Onyx Directory Traversal Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI. A successful exploit of this vulnerability might lead to escalation of privileges and information disclosure.
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NVIDIA Onyx switches. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the /admin/launch endpoint. When parsing the script query parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the device.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-12-02 CVE Reserved
- 2024-08-09 CVE Published
- 2024-10-09 CVE Updated
- 2024-10-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-35: Path Traversal: '.../...//'
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://nvidia.custhelp.com/app/answers/detail/a_id/5563 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
NVIDIA Search vendor "NVIDIA" | Mellanox OS Search vendor "NVIDIA" for product "Mellanox OS" | 3.11.4000 Search vendor "NVIDIA" for product "Mellanox OS" and version "3.11.4000" | en |
Affected
| ||||||
NVIDIA Search vendor "NVIDIA" | Mellanox OS Search vendor "NVIDIA" for product "Mellanox OS" | 3.11.2200 Search vendor "NVIDIA" for product "Mellanox OS" and version "3.11.2200" | en |
Affected
| ||||||
NVIDIA Search vendor "NVIDIA" | Mellanox OS Search vendor "NVIDIA" for product "Mellanox OS" | 3.10.4400 Search vendor "NVIDIA" for product "Mellanox OS" and version "3.10.4400" | en |
Affected
| ||||||
NVIDIA Search vendor "NVIDIA" | Skyway Search vendor "NVIDIA" for product "Skyway" | 8.2.2200 Search vendor "NVIDIA" for product "Skyway" and version "8.2.2200" | en |
Affected
| ||||||
NVIDIA Search vendor "NVIDIA" | Skyway Search vendor "NVIDIA" for product "Skyway" | 8.1.4400 Search vendor "NVIDIA" for product "Skyway" and version "8.1.4400" | en |
Affected
| ||||||
NVIDIA Search vendor "NVIDIA" | MetroX-3 XC Search vendor "NVIDIA" for product "MetroX-3 XC" | 18.2.2200 Search vendor "NVIDIA" for product "MetroX-3 XC" and version "18.2.2200" | en |
Affected
| ||||||
NVIDIA Search vendor "NVIDIA" | MetroX-2 Search vendor "NVIDIA" for product "MetroX-2" | 3.11.4000 Search vendor "NVIDIA" for product "MetroX-2" and version "3.11.4000" | en |
Affected
|