CVE-2024-0105
NVIDIA ConnectX Firmware contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue. A successful exploit of this vulnerability may lead to denial of service, data tampering, and limited information disclosure.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.9
- CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
- EPSS probability
- 0.27%
- CWE
- CWE-274
- Published
- 2024-11-01
- Last modified
- 2026-03-13
Affected products
- NVIDIA ConnectX4
- NVIDIA ConnectX4 LX
- NVIDIA ConnectX GA
- NVIDIA ConnectX LTS22
- NVIDIA ConnectX LTS23
- NVIDIA BlueField 1
- NVIDIA BlueField GA
- NVIDIA BlueField LTS22
Weakness type
Related vulnerabilities
- CVE-2026-62764 — Apache Accumulo: A user can trigger a graceful shutdown of services without the relevant system permissions
- CVE-2025-54511 — Improper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an...
- CVE-2026-33005 — Apache OpenMeetings: Insufficient checks in FileWebService
- CVE-2025-62175 — Mastodon streaming API fails to disconnect disabled and suspended users
- CVE-2023-20516 — Improper handling of insufficiency privileges in the ASP could allow a privileged attacker to...
- CVE-2025-20177 — Cisco IOS XR Software Image Verification Bypass Vulnerability
- CVE-2024-46974 — GPU DDK - Arbitrary write of read-only dmabuf
- CVE-2025-20156 — Cisco Meeting Management Client-Server Privilege Escalation Vulnerability