Database/Firmware, BMC & network fabric
Dell Enterprise SONiC OS (SSH cryptographic key): A cryptographic key weakness in SONiC's SSH implementation lets
Impact
A cryptographic key weakness in SONiC's SSH implementation lets an unauthenticated remote attacker exploit the switch. Shared or predictable SSH host keys across a product line mean an attacker can impersonate any switch to your automation, harvesting the credentials your config-management pushes. CVE-2025-38741 is the same class recurring in SONiC 4.5.0, which tells you it is a build-pipeline problem, not a one-off.
Who can reach it
Unauthenticated, remote — anyone able to interpose on or reach the switch's SSH service.
What to do
NOS image upgrade plus reboot, and then **regenerate the switch's SSH host keys** — the upgrade alone does not replace a key that was already weak or shared. Update your automation's known_hosts afterwards. Verify host-key uniqueness across the fleet as a standing check.
References
Related entries
- Intel OpenBMC firmware (before version 0.72) - network-facing service: An unauthenticated caller reads out of boundsCVE-2022-35729 · Intel OpenBMC firmware (before version 0.72) - network-facing serviceHigh
- AMI MegaRAC: Default credentials for the `sysadmin` account, shell access to the BMCCVE-2022-40242 · AMI MegaRACHigh
- Linux kernel (drivers/infiniband/hw/irdma): A permanent kernel hang once any queue-pair goes to error.CVE-2022-48694 · Linux kernel (drivers/infiniband/hw/irdma)High
- Linux kernel (drivers/infiniband/sw/siw): A remote peer crashes the node during connection setup. When the MPACVE-2022-50136 · Linux kernel (drivers/infiniband/sw/siw)High
- Linux kernel (drivers/infiniband/sw/rxe): A null-pointer dereference panics the node whenever queue-pair creation failsCVE-2022-50885 · Linux kernel (drivers/infiniband/sw/rxe)High
- Dell Enterprise SONiC OS (authentication component): Uncontrolled resource consumption in SONiC's authenticationCVE-2023-24574 · Dell Enterprise SONiC OS (authentication component)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.