Permissions, Privileges, and Access Controls in BlueField - CVE-2024-0106

 

Permissions, Privileges, and Access Controls in BlueField - CVE-2024-0106

Published: October 30, 2024


Vulnerability identifier: #VU99497
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-0106
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: nVidia
Affected software:
BlueField

Detailed vulnerability description

The vulnerability allows a local user to compromise the target system.

The vulnerability exists due to improper handling of insufficient privileges, which leads to denial of service, data tampering and limited information disclosure.


How to mitigate CVE-2024-0106

Install updates from vendor's website.

Sources