#VU99497 Permissions, Privileges, and Access Controls in BlueField - CVE-2024-0106
Published: October 30, 2024
Vulnerability identifier: #VU99497
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-0106
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
BlueField
BlueField
Software vendor:
nVidia
nVidia
Description
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to improper handling of insufficient privileges, which leads to denial of service, data tampering and limited information disclosure.
Remediation
Install updates from vendor's website.