Database/Firmware, BMC & network fabric
Dell Enterprise SONiC (sensitive information in log files): Sensitive information is written into log files
Impact
Sensitive information is written into log files on the switch. Switch logs are routinely shipped wholesale to a central syslog or observability stack that far more people can read than can log into the switch — so secrets written to the log leak to a much wider audience than the device's own access control implies.
Who can reach it
Anyone with read access to the switch's logs or to the log aggregation pipeline they are shipped to.
What to do
Upgrade to Enterprise SONiC 4.4.1 or 4.2.3 or later — NOS image upgrade plus reboot. Also purge historical logs from your aggregator and rotate anything that appeared in them; that cleanup is the part people skip.
References
Related entries
- Arista EOS (ingress ACL enforcement on ethernet/LAG): With IPv4 ingress, MAC ingress, or IPv6 standard ingress ACLsCVE-2025-2826 · Arista EOS (ingress ACL enforcement on ethernet/LAG)Unscored
- Linux kernel mlxbf-bootctl (BlueField secure boot fuse state): The BlueField boot-control driver mishandles the sysfsCVE-2025-37866 · Linux kernel mlxbf-bootctl (BlueField secure boot fuse state)Unscored
- libtpms (CryptHmacSign, vTPM): Out-of-bounds read when signKey and signScheme are mismatched, aborting the vTPMCVE-2025-49133 · libtpms (CryptHmacSign, vTPM)Unscored
- Juniper Junos OS / Junos OS Evolved (rpd BGP session handling): A genuine, valid BGP UPDATE message resets a live BGPCVE-2025-52953 · Juniper Junos OS / Junos OS Evolved (rpd BGP session handling)Unscored
- Juniper Junos OS / Junos OS Evolved (annotate configuration command): The `annotate` configuration command can be usedCVE-2025-52989 · Juniper Junos OS / Junos OS Evolved (annotate configuration command)Unscored
- Juniper Junos OS (QFX5000-Series, EX4600-Series): A physical-access path into affected QFX5000 and EX4600 switchesCVE-2025-59957 · Juniper Junos OS (QFX5000-Series, EX4600-Series)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.