8.0 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Adjacent (A)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Adjacent (A)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
Activity log
- Created suggestion
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in …
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could run an unauthorized command. A successful exploit of this vulnerability might lead to escalation of privileges.
References
Affected products
- ==All versions prior to 25.02.4282
- ==All versions prior to 25.02.5030
- ==All versions prior to 1.3 - 25.02.244
- ==All versions prior to 5.14 (5.13.x, 5.12.x, and older GA versions)
- ==All versions prior to 5.9.4
- ==All versions prior to 5.11.4
Package maintainers
-
@stigtsp Stig Palmquist <stig@stig.io>