CVE-2024-42018

CVSS 3.1 Score 7.7 of 10 (high)

Details

Published Oct 11, 2024
Updated: Nov 6, 2024
CWE ID 922

Summary

CVE-2024-42018 is a vulnerability affecting Atos Eviden SMC xScale versions prior to 1.6.6. During node initialization, sensitive configuration parameters containing credentials are retrieved from management nodes, which may compromise the security of HPC configurations. Although normal mitigation measures prevent unprivileged users from accessing these parameters, they do not persist after a diskful node reboot. The root cause of this issue is the misconfiguration of iptables in the cloudinit settings, with the mitigation measure placed incorrectly in the runcmd section instead of the bootcmd section.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share