CVE-2024-42018
CVSS 3.1 Score 7.7 of 10 (high)
Details
Summary
CVE-2024-42018 is a vulnerability affecting Atos Eviden SMC xScale versions prior to 1.6.6. During node initialization, sensitive configuration parameters containing credentials are retrieved from management nodes, which may compromise the security of HPC configurations. Although normal mitigation measures prevent unprivileged users from accessing these parameters, they do not persist after a diskful node reboot. The root cause of this issue is the misconfiguration of iptables in the cloudinit settings, with the mitigation measure placed incorrectly in the runcmd section instead of the bootcmd section.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.