NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI. A successful exploit of this vulnerability might lead to escalation of privileges and information disclosure.
| Software | From | Fixed in |
|---|---|---|
| nvidia / mlnx-os | - | 3.12.1002 |
| nvidia / mlnx-os | - | 3.10.4500 |
| nvidia / mlnx-os | 3.11.0000 | 3.11.2302 |
| nvidia / onyx | - | 3.10.4504 |
| nvidia / mlnx-gw | - | 8.1.4500 |
| nvidia / mlnx-gw | - | 8.2.2300 |
| nvidia / nvda-os_xc | - | 18.2.2200 |