Cyber Security News

NVIDIA Base Command Manager Vulnerability Let Attackers Remote Code

NVIDIA has issued a security advisory addressing a critical vulnerability (CVE-2024-0138) discovered in its Base Command Manager software.

This flaw, located within the CMDaemon component, poses significant risks, including the potential for remote code execution, denial of service, privilege escalation, information disclosure, and data tampering.

Vulnerability Overview

The vulnerability arises from a missing authentication mechanism (CWE-862) in the CMDaemon component.

This critical flaw can be exploited remotely without any prerequisites, such as user interaction or special privileges, making it highly dangerous.

Leveraging 2024 MITRE ATT&CK Results for SME & MSP Cybersecurity Leaders – Attend Free Webinar

The vulnerability is assigned a Common Vulnerability Scoring System (CVSS) v3.1 base score of 9.8, categorizing it as “Critical.”

The vulnerability, classified under CWE-862 (Missing Authorization), is particularly dangerous because it can be exploited remotely without requiring user interaction or special privileges.

With a CVSS v3.1 base score of 9.8, this flaw is rated as “Critical.” The severity highlights the potential for widespread impact across systems using the affected software.

If successfully exploited, attackers could remotely execute arbitrary code, disrupt services, escalate user privileges, obtain sensitive information, or tamper with data.

Affected Products and Updates

The affected software versions and updates are summarized below:

CVE IDAffected ProductPlatformAffected VersionUpdated Version
CVE-2024-0138NVIDIA Base Command ManagerAll10.24.0910.24.09a

NVIDIA confirmed that earlier versions, including 10.24.07 and earlier, are not impacted by this vulnerability.

To mitigate the issue, NVIDIA recommends updating the CMDaemon component on all head nodes and software images.

After applying the update, systems should be rebooted or resynchronized with the updated software image to ensure the fix is fully implemented.

These measures are essential to eliminate the vulnerability and protect systems from potential exploitation.

NVIDIA advises users to stay informed about ongoing security developments by visiting the NVIDIA Product Security page.

This platform provides access to the latest security bulletins, subscription options for notifications, and resources for reporting potential security concerns.

By ensuring their systems are up to date and monitoring security updates, users can minimize risks and maintain a secure computing environment.

Are you from SOC/DFIR Teams? – Analyse Malware & Phishing with ANY.RUN -> Try for Free



Dhivya

Divya is a Senior Journalist at Cyber Security news covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago