Dell Enterprise Sonic Os vulnerabilities
9 known vulnerabilities affecting dell/enterprise_sonic_os.
Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH5MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2023-32484P2CRITICALCVSS 9.8v 3.5.xv4.0.x+1 more2024-02-15
CVE-2023-32484 [CRITICAL] CWE-20 CVE-2023-32484: Dell Networking Switches running Enterprise SONiC versions 4.1.0, 4.0.5, 3.5.4 and below contains a
Dell Networking Switches running Enterprise SONiC versions 4.1.0, 4.0.5, 3.5.4 and below contains an improper input validation vulnerability. A remote unauthenticated malicious user may exploit this vulnerability and escalate privileges up to the highest administrative level. This is a Critical vulnerability affecting certain protocols, Dell recomme
nvd
CVE-2024-45764P2CRITICALCVSS 9.8≥ N/A, < 4.1.6≥ N/A, < 4.2.22024-11-08
CVE-2024-45764 [CRITICAL] CWE-304 CVE-2024-45764: Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authenticat
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. This is a critical severity vulnerability so Dell recommends customers to upgrade at the earliest
nvd
CVE-2024-45763P3HIGHCVSS 7.2≥ N/A, < 4.1.6≥ N/A, < 4.2.22024-11-08
CVE-2024-45763 [HIGH] CWE-78 CVE-2024-45763: Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. This is a critical severity vulnerability so Dell recommends c
nvd
CVE-2024-45765P3HIGHCVSS 7.2≥ N/A, < 4.1.6≥ N/A, < 4.2.22024-11-08
CVE-2024-45765 [HIGH] CWE-78 CVE-2024-45765: Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. This is a critical severity vulnerability as it allows high pr
nvd
CVE-2025-38741P3HIGHCVSS 7.5v4.5.0≥ 4.5.0, < 4.5.0a2025-08-04
CVE-2025-38741 [HIGH] CWE-321 CVE-2025-38741: Dell Enterprise SONiC OS, version 4.5.0, contains a cryptographic key vulnerability in SSH. An unaut
Dell Enterprise SONiC OS, version 4.5.0, contains a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to communication.
nvd
CVE-2023-24574P3HIGHCVSS 7.5≤ 3.5.3, 3.5.4, 4.0.0, 4.0.1, 4.0.22023-02-02
CVE-2023-24574 [HIGH] CWE-400 CVE-2023-24574: Dell Enterprise SONiC OS, 3.5.3, 4.0.0, 4.0.1, 4.0.2, contains an "Uncontrolled Resource Consumptio
Dell Enterprise SONiC OS, 3.5.3, 4.0.0, 4.0.1, 4.0.2, contains an "Uncontrolled Resource Consumption vulnerability" in authentication component. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to uncontrolled resource consumption by creating permanent home directories for unauthenticated users.
nvd
CVE-2022-34425P3HIGHCVSS 7.5≥ unspecified, < 4.0.22022-10-10
CVE-2022-34425 [HIGH] CWE-321 CVE-2022-34425: Dell Enterprise SONiC OS, 4.0.0, 4.0.1, contain a cryptographic key vulnerability in SSH. An unauthe
Dell Enterprise SONiC OS, 4.0.0, 4.0.1, contain a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to communication.
nvd
CVE-2021-36309P4MEDIUMCVSS 6.5≤ 3.3.0≥ unspecified, < 3.4.02021-10-01
CVE-2021-36309 [MEDIUM] CWE-256 CVE-2021-36309: Dell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vu
Dell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vulnerability. An authenticated malicious user with access to the system may use the TACACS\Radius credentials stored to read sensitive information and use it in further attacks.
nvd
CVE-2025-23374P4MEDIUMCVSS 4.9≥ N/A, < 4.4.1≥ N/A, < 4.2.32025-01-30
CVE-2025-23374 [MEDIUM] CWE-532 CVE-2025-23374: Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s
Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
nvd