### #NVIDIAUpdate #CVE2024 #BaseCommandManager
Summary: NVIDIA has released a critical security update for its Base Command Manager software to address a severe vulnerability (CVE-2024-0138) that could allow attackers to execute code and escalate privileges. Users are urged to update to version 10.24.09a immediately to mitigate potential risks.
Threat Actor: Unknown | unknown
Victim: NVIDIA Base Command Manager Users | NVIDIA Base Command Manager Users
Key Point :
- The vulnerability, tracked as CVE-2024-0138, has a CVSS score of 9.8, indicating high severity.
- Exploitation could lead to code execution, denial of service, privilege escalation, information disclosure, and data tampering.
- Users must update to version 10.24.09a to secure their systems against this vulnerability.
- NVIDIA has confirmed that earlier versions (10.24.07 and below) are not affected by this flaw.
- Clear instructions for updating have been provided by NVIDIA to ensure user compliance.

NVIDIA has issued a critical security update for its Base Command Manager software, addressing a vulnerability that could open systems to a range of serious attacks. The flaw, tracked as CVE-2024-0138 and assigned a CVSS score of 9.8, resides in the CMDaemon component and could allow attackers to execute code, escalate privileges, and tamper with data.
According to NVIDIAβs security bulletin, βA successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.β This high-severity vulnerability affects NVIDIA Base Command Manager version 10.24.09.
To mitigate this risk, NVIDIA urges users to update to the patched version 10.24.09a immediately. The update can be obtained through the BCM Package Repository.
The company has provided clear instructions for implementing the update:
- Update to the most recent version of CMdaemon on the head nodes and in all software images.
- Update the nodes by either rebooting them or resynchronizing them with the software image.
Fortunately, NVIDIA has confirmed that βBase Command Manager 10.24.07 and earlier versions do not contain this vulnerability.β However, it is crucial for users of version 10.24.09 to apply the update promptly to ensure their systems are protected.
Given the critical nature of this vulnerability, which could enable an attacker to gain deep access into an organizationβs systems, timely application of this patch is crucial. Organizations using NVIDIA Base Command Manager should prioritize updating their systems to safeguard against the risk of exploitation.
Related Posts:
Source: https://securityonline.info/nvidia-base-command-manager-update-patches-cve-2024-0138-cvss-9-8