« Volver al listado

CVE-2024-0130

Estado: AplazadaAlta (8.8)—

NVIDIA UFM Enterprise, UFM Appliance, and UFM CyberAI contain a vulnerability where an attacker can cause an improper authentication issue by sending a malformed request through the Ethernet management interface. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and information disclosure.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Red adyacente (AV:A), sin privilegios, requiere acceso a interfaz Ethernet de gestión. Improper authentication (CWE-287) permite obtener acceso a cuentas válidas (T1078), escalar privilegios (T1068) y leer datos sensibles.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (3)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-0130",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-0130",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-12-09T22:09:20.738912Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@nvidia.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@nvidia.com",
      "affectedData": [
        {
          "vendor": "NVIDIA",
          "product": "UFM Enterprise GA",
          "versions": [
            {
              "status": "affected",
              "version": "6.15.x, 6.16.x, 6.17.x"
            }
          ],
          "platforms": [
            "RHEL 8",
            "RHEL 9",
            "Ubuntu20",
            "Ubuntu22"
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "NVIDIA",
          "product": "UFM Enterprise LTS23",
          "versions": [
            {
              "status": "affected",
              "version": "6.15.x LTS prior to 6.15.6-4 LTS"
            }
          ],
          "platforms": [
            "RHEL 7",
            "RHEL 8",
            "RHEL 9",
            "Ubuntu18",
            "Ubuntu20",
            "Ubuntu22"
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "NVIDIA",
          "product": "UFM Enterprise Appliance GA",
          "versions": [
            {
              "status": "affected",
              "version": "1.6.x, 1.7.x, 1.8.x"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "NVIDIA",
          "product": "UFM Enterprise Appliance LTS23",
          "versions": [
            {
              "status": "affected",
              "version": "1.6.x LTS prior to 1.6.6-1 LTS"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "NVIDIA",
          "product": "UFM SDN Appliance GA",
          "versions": [
            {
              "status": "affected",
              "version": "4.14.x, 4.15.x, 4.16.x"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "NVIDIA",
          "product": "UFM SDN Appliance LTS23",
          "versions": [
            {
              "status": "affected",
              "version": "4.14.x LTS prior to 4.14.6.4 LTS"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "NVIDIA",
          "product": "UFM CyberAI GA",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.x, 2.7.x, 2.8.x"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "NVIDIA",
          "product": "UFM CyberAI LTS23",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.1-3 LTS"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-12-06T20:15:23.543",
  "references": [
    {
      "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5584",
      "source": "psirt@nvidia.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@nvidia.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "NVIDIA UFM Enterprise, UFM Appliance, and UFM CyberAI contain a vulnerability where an attacker can cause an improper authentication issue by sending a malformed request through the Ethernet management interface. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and information disclosure."
    },
    {
      "lang": "es",
      "value": "NVIDIA UFM Enterprise, UFM Appliance y UFM CyberAI contienen una vulnerabilidad que permite a un atacante provocar un problema de autenticación incorrecto al enviar una solicitud mal formada a través de la interfaz de administración de Ethernet. Una explotación exitosa de esta vulnerabilidad podría provocar una escalada de privilegios, manipulación de datos, denegación de servicio y divulgación de información."
    }
  ],
  "lastModified": "2026-06-17T06:52:50.447",
  "sourceIdentifier": "psirt@nvidia.com"
}