GPU VulnDB

Database/Control plane, storage & DevOps

A10 Thunder ADC (CsrRequestView): An authenticated attacker can inject a system-call payload through the CsrRequestView

CVE-2024-30368Control plane, storage & DevOpsZDI-24-524curated

Impact

An authenticated attacker can inject a system-call payload through the CsrRequestView component (used for certificate-signing-request handling), running arbitrary code on the load balancer with the privileges of the vulnerable process.

Who can reach it

Requires authentication first — the advisory doesn't specify a high privilege tier, meaning even a lower-privileged operator account may be enough to trigger it.

What to do

Software upgrade to the fixed ACOS release per A10's advisory for CVE-2024-30368/CVE-2024-30369 (the two ship together). Upgrade and reboot each Thunder ADC instance; if it's fronting inference traffic, plan for a failover to a standby unit during the upgrade rather than a hard outage.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.