NVIDIA Product Security Update Advisory

Overview

An update has been released to address vulnerabilities in NVIDIA Products. Users of the affected versions are advised to update to the latest version.

 

Affected Products

 

CVE-2024-0122

  • DLS component of NVIDIA License System versions: 2.1, 3.1, 3.1.1, 3.1.2, 3.1.3
  • DLS component of NVIDIA License System versions: 3.2, 3.3, 3.3.1

 

CVE-2024-0138

  • NVIDIA Base Command Manager version: 10.24.09

 

 

Resolved Vulnerabilities

 

Vulnerability in all appliance platforms in NVIDIA Delegated Licensing Service that could allow an attacker to perform unauthorized actions (CVE-2024-0122)

Missing authentication vulnerability in the CMDaemon component of NVIDIA Base Command Manager (CVE-2024-0138)

 

Vulnerability Patches

 

Vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2024-0122

  • DLS component of NVIDIA License System version: 3.14
  • DLS component of NVIDIA License System version: 3.4

 

CVE-2024-0138

  • NVIDIA Base Command Manager version: 10.24.09a

 

 

References Sites

 

[1] Security Bulletin: NVIDIA Delegated License System – November 2024

https://nvidia.custhelp.com/app/answers/detail/a_id/5570

[2] Security Bulletin: NVIDIA Base Command Manager – November 2024

https://nvidia.custhelp.com/app/answers/detail/a_id/5595