GPU VulnDB

Database/Firmware, BMC & network fabric

Dell Enterprise SONiC (authentication): A critical step in authentication is missing, so an unauthenticated remote

CVE-2024-45764Firmware, BMC & network fabricDSA-2024-449curated

Impact

A critical step in authentication is missing, so an unauthenticated remote attacker bypasses the protection mechanism and gets into the switch. SONiC is increasingly the NOS of choice for cost-driven GPU buildouts precisely because it is open and cheap; this is the reminder that the open NOS ecosystem has the same class of front-door bugs as the incumbents, with a shorter advisory history to check against.

Who can reach it

Unauthenticated, remote — reachability to the switch's management services is the only requirement.

What to do

Upgrade Dell Enterprise SONiC past 4.1.x/4.2.x to a fixed release, which means a NOS image install and switch reboot per device. In a SONiC fabric that is a full image swap, not a patch — budget a maintenance window per leaf and stage it across MLAG pairs. Restrict management-interface reachability in the meantime.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.