Dell Networking Switches running Enterprise SONiC versions 4.1.0, 4.0.5, 3.5.4 and below contains an improper input validation vulnerability. A remote unauthenticated malicious user may exploit this vulnerability and escalate privileges up to the highest administrative level. This is a Critical vulnerability affecting certain protocols, Dell recommends customers to upgrade at the earliest opportunity.
2024-02-15T13:15:45.553
2025-01-23T16:59:24.473
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dell | enterprise_sonic_distribution | < 3.5.5 | Yes |
Operating System | dell | enterprise_sonic_distribution | < 4.0.6 | Yes |
Operating System | dell | enterprise_sonic_distribution | 4.1.0 | Yes |