Database/Firmware, BMC & network fabric
Dell Enterprise SONiC OS (input validation): Improper input validation on Dell Networking switches running Enterprise
Impact
Improper input validation on Dell Networking switches running Enterprise SONiC, exploitable by a remote unauthenticated attacker. Affects 4.1.0, 4.0.5, 3.5.4 and below — i.e. essentially every SONiC release before the 2024 hardening pass. If you bought Dell switches with SONiC for a cost-optimised GPU buildout in 2022-2023 and have not touched the NOS since, this is live.
Who can reach it
Unauthenticated, remote to the switch.
What to do
NOS image upgrade and switch reboot. On SONiC that is a full image install, so the switch is down for minutes — stage across MLAG pairs. Put SONiC management interfaces on an isolated OOB network as the standing control.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.