CVE-2024-42018
Last modified
CVE-2024-42018 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. An issue was discovered in Atos Eviden SMC xScale before 1.6.6. During initialization of nodes, some configuration parameters are retrieved from management nodes. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
An issue was discovered in Atos Eviden SMC xScale before 1.6.6. During initialization of nodes, some configuration parameters are retrieved from management nodes. These parameters embed credentials whose integrity and confidentiality may be important to the security of the HPC configuration. Because these parameters are needed for initialization, there is no available mechanism to ensure access control on the management node, and a mitigation measure is normally put in place to prevent access to unprivileged users. It was discovered that this mitigation measure does not survive a reboot of diskful nodes. (Diskless nodes are not at risk.) The mistake lies in the cloudinit configuration: the iptables configuration should have been in the bootcmd instead of the runcmd section.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-42018?
How severe is CVE-2024-42018?
How do I fix CVE-2024-42018?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-4201A cross-site scripting issue has been discovered in GitLab a…4.4
- CVE-2024-42010mod_css_styles in Roundcube through 1.5.7 and 1.6.x through …7.5
- CVE-2024-42011The Spotify app 8.9.58 for iOS has a buffer overflow in its …7.5
- CVE-2024-42012GRAU DATA Blocky before 3.1 stores passwords encrypted rathe…5.7
- CVE-2024-42013In GRAU DATA Blocky before 3.1, Blocky-Gui has a Client-Side…6.4
- CVE-2024-42017An issue was discovered in Atos Eviden iCare 2.7.1 through 2…10
- CVE-2024-42019A vulnerability that allows an attacker to access the NTLM h…8
- CVE-2024-4202In Progress® Telerik® Reporting versions prior to 2024 Q2 (1…8.6
- CVE-2024-42020A Cross-site-scripting (XSS) vulnerability exists in the Rep…5.4
- CVE-2024-42021An improper access control vulnerability allows an attacker …6.5
- CVE-2024-42022An incorrect permission assignment vulnerability allows an a…5.3
- CVE-2024-42023An improper access control vulnerability allows low-privileg…8.8
Are you affected by CVE-2024-42018?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
