Database/Firmware, BMC & network fabric
Dell SmartFabric OS10 (uncontrolled resource consumption): A remote unauthenticated host can exhaust resources on an
CVSS 7.5CVE-2024-37125Firmware, BMC & network fabriccurated
Impact
A remote unauthenticated host can exhaust resources on an OS10 switch across 10.5.3.x through 10.5.6.x. No credentials, no adjacency requirement beyond IP reachability — so any tenant workload that can address the switch can attempt it.
Who can reach it
Unauthenticated remote host with IP reachability to the switch.
What to do
OS10 upgrade plus reload. Interim: control-plane policing and management ACLs restricting who can address the switch at all — live config changes that are worth having permanently.
References
Related entries
- Sunbird DCIM dcTrack v9.1.2 - ticket location RBAC: Incorrect access control lets an attacker create or update ticketsCVE-2024-37775 · Sunbird DCIM dcTrack v9.1.2 - ticket location RBACHigh
- Dell SmartFabric OS10 (command injection): Command injection in SmartFabric OS10 10.5.5.4-10.5.5.10 and 10.5.6.xCVE-2024-38486 · Dell SmartFabric OS10 (command injection)High
- Linux kernel - RDMA/rxe unreliable datagram responder, drivers/infiniband/sw/rxe/rxe_resp.c: The IB architecture says aCVE-2024-40992 · Linux kernel - RDMA/rxe unreliable datagram responder, drivers/infiniband/sw/rxe/rxe_resp.cHigh
- Linux kernel NVMe-oF RDMA target (nvmet, uninitialised completion-entry result field): This is a straight kernel-stackCVE-2024-41079 · Linux kernel NVMe-oF RDMA target (nvmet, uninitialised completion-entry result field)High
- Linux kernel InfiniBand core (ib_umad): ib_umad kept received management datagrams on an unbounded listCVE-2024-42145 · Linux kernel InfiniBand core (ib_umad)High
- AMI AptioV BIOS (TOCTOU race condition): Firmware TOCTOU race allowing execution of arbitrary code on the target deviceCVE-2024-42444 · AMI AptioV BIOS (TOCTOU race condition)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.