NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could run an unauthorized command. A successful exploit of this vulnerability might lead to escalation of privileges.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Cumulus_linux | Nvidia | * | 5.14.0 (excluding) |
| Cumulus_linux | Nvidia | 5.9.0 (including) | 5.9.4 (excluding) |
| Cumulus_linux | Nvidia | 5.11.0 (including) | 5.11.4 (excluding) |