Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-32462


Dell OS10 Networking Switches running 10.5.2.x and above contain an OS command injection vulnerability when using remote user authentication. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands and possible system takeover. This is a critical vulnerability as it allows an attacker to cause severe damage. Dell recommends customers to upgrade at the earliest opportunity.


Published

2024-02-15T13:15:45.280

Last Modified

2025-01-23T17:02:15.480

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System dell smartfabric_os10 < 10.5.2.12 Yes
Operating System dell smartfabric_os10 < 10.5.3.8 Yes
Operating System dell smartfabric_os10 < 10.5.4.8 Yes
Operating System dell smartfabric_os10 10.5.5.0 Yes
Operating System dell smartfabric_os10 10.5.5.1 Yes
Operating System dell smartfabric_os10 10.5.5.2 Yes
Operating System dell smartfabric_os10 10.5.5.3 Yes

References