SB2025051537 - Lenovo update for NVIDIA ConnectX
Published: May 15, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2024-0105)
The vulnerability allows a remote user on the local network to compromise the target system.
The vulnerability exists due to improper handling of insufficient privileges, which leads to denial of service, data tampering and limited information disclosure.
2) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2024-0106)
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to improper handling of insufficient privileges, which leads to denial of service, data tampering and limited information disclosure.
Remediation
Install update from vendor's website.