Database/Firmware, BMC & network fabric
Dell Enterprise SONiC OS (input validation): Improper input validation on Dell Networking switches running Enterprise
Impact
Improper input validation on Dell Networking switches running Enterprise SONiC, exploitable by a remote unauthenticated attacker. Affects 4.1.0, 4.0.5, 3.5.4 and below — i.e. essentially every SONiC release before the 2024 hardening pass. If you bought Dell switches with SONiC for a cost-optimised GPU buildout in 2022-2023 and have not touched the NOS since, this is live.
Who can reach it
Unauthenticated, remote to the switch.
What to do
NOS image upgrade and switch reboot. On SONiC that is a full image install, so the switch is down for minutes — stage across MLAG pairs. Put SONiC management interfaces on an isolated OOB network as the standing control.
References
Related entries
- Dell SmartFabric Storage Software: Improper input validation in Dell SmartFabric Storage Software 1.3 and lowerCVE-2023-32485 · Dell SmartFabric Storage SoftwareCritical
- CyberPower PowerPanel Enterprise DCIM - username handling: Authentication bypass: appending a non-printable characterCVE-2023-3265 · CyberPower PowerPanel Enterprise DCIM - username handlingCritical
- CyberPower PowerPanel Enterprise DCIM - LDAP authentication path: If LDAP authentication is selectedCVE-2023-3266 · CyberPower PowerPanel Enterprise DCIM - LDAP authentication pathCritical
- Supermicro BMC email/SMTP alert notification handler (H12DST-B): Command execution as root on the BMC, reached throughCVE-2023-35861 · Supermicro BMC email/SMTP alert notification handler (H12DST-B)Critical
- Juniper Junos OS J-Web (EX/SRX): Unauthenticated remote code execution by setting `PHPRC` through a crafted J-WebCVE-2023-36845 · Juniper Junos OS J-Web (EX/SRX)Critical
- Insyde InsydeH2O (AsfSecureBootDxe): Stack buffer overflow leading to arbitrary code execution during the DXE phaseCVE-2023-39281 · Insyde InsydeH2O (AsfSecureBootDxe)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.