Database/Firmware, BMC & network fabric
Dell Enterprise SONiC (authentication): A critical step in authentication is missing, so an unauthenticated remote
Impact
A critical step in authentication is missing, so an unauthenticated remote attacker bypasses the protection mechanism and gets into the switch. SONiC is increasingly the NOS of choice for cost-driven GPU buildouts precisely because it is open and cheap; this is the reminder that the open NOS ecosystem has the same class of front-door bugs as the incumbents, with a shorter advisory history to check against.
Who can reach it
Unauthenticated, remote — reachability to the switch's management services is the only requirement.
What to do
Upgrade Dell Enterprise SONiC past 4.1.x/4.2.x to a fixed release, which means a NOS image install and switch reboot per device. In a SONiC fabric that is a full image swap, not a patch — budget a maintenance window per leaf and stage it across MLAG pairs. Restrict management-interface reachability in the meantime.
References
Related entries
- Arista EOS OSPFv3: crafted packet restarts the routing agentCVE-2026-73455 · Arista EOS (OSPFv3 routing agent)High
- Linux kernel InfiniBand uverbs (ib_uverbs / ib_umem_get, drivers/infiniband/core/umem.c): The canonical RDMA isolationCVE-2014-8159 · Linux kernel InfiniBand uverbs (ib_uverbs / ib_umem_get, drivers/infiniband/core/umem.c)High
- Dell iDRAC7 / iDRAC8 firmware before 2.40.40.40 - racadm CLI string injection: A string injection escapes theCVE-2016-5685 · Dell iDRAC7 / iDRAC8 firmware before 2.40.40.40 - racadm CLI string injectionHigh
- Cisco NX-OS / FXOS (LLDP parser): A malformed LLDP frame reloads the switch. LLDP is enabled by default on essentiallyCVE-2018-0395 · Cisco NX-OS / FXOS (LLDP parser)High
- Dell iDRAC7 / iDRAC8 / iDRAC9 (SNMP agent): Command injection in the iDRAC SNMP agent gives an attacker who alreadyCVE-2018-1244 · Dell iDRAC7 / iDRAC8 / iDRAC9 (SNMP agent)High
- Dell iDRAC9 (Redfish): Redfish interface permission-check flaw enabling privilege escalation to adminCVE-2018-15774 · Dell iDRAC9 (Redfish)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.