GPU VulnDB

Database/Firmware, BMC & network fabric

Dell Enterprise SONiC OS (authentication component): Uncontrolled resource consumption in SONiC's authentication

CVSS 7.5CVE-2023-24574Firmware, BMC & network fabriccurated

Impact

Uncontrolled resource consumption in SONiC's authentication component, reachable by an unauthenticated remote attacker. Exhausting the authentication path is a good denial of service because it locks *you* out of the switch at the same time it stays up forwarding — you lose the ability to respond.

Who can reach it

Unauthenticated, remote to the switch management services on Enterprise SONiC 3.5.3, 4.0.0, 4.0.1, 4.0.2.

What to do

NOS image upgrade plus reboot. Interim: rate-limit and ACL the management interface so only your jump hosts can reach the authentication endpoints — a live config change that also preserves your own access.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.