Database/Firmware, BMC & network fabric
Dell Enterprise SONiC OS 4.5.0 (SSH cryptographic key): The SSH cryptographic-key weakness recurring in Enterprise
Impact
The SSH cryptographic-key weakness recurring in Enterprise SONiC 4.5.0, three years after the same class was fixed in 4.0.x. For an operator the lesson is that SONiC host-key uniqueness is not something to assume from a version number — check it directly on every switch you deploy.
Who can reach it
Unauthenticated, remote against the switch's SSH service.
What to do
NOS image upgrade plus reboot, then regenerate host keys and refresh your automation's trust store. Consider adding a fleet-wide host-key uniqueness assertion to your provisioning tests.
References
Related entries
- Fujitsu / Fsas Technologies iRMC S6 BMC (M5-generation servers): A length-boundary bug in BMC authenticationCVE-2025-65002 · Fujitsu / Fsas Technologies iRMC S6 BMC (M5-generation servers)High
- IBM PowerVM partition firmware: malformed network-boot packet yields code execution inside the booting partitionCVE-2026-18821 · IBM PowerVM partition firmware (network boot packet handling)High
- Linux kernel NVMe-oF TCP target (nvmet-tcp, H2C_DATA PDU before CONNECT): Nvmet_tcp_build_pdu_iovec() dereferences cmdCVE-2026-22998 · Linux kernel NVMe-oF TCP target (nvmet-tcp, H2C_DATA PDU before CONNECT)High
- Linux kernel SoftiWARP receive path (siw_qp_rx, siw_tcp_rx_data header processing): When siw_get_hdr() rejects a headerCVE-2026-23242 · Linux kernel SoftiWARP receive path (siw_qp_rx, siw_tcp_rx_data header processing)High
- GNU FreeIPMI's ipmi-oem tool before version 1.6.17: The direction of trust is what makes this operator-relevantCVE-2026-33554 · GNU FreeIPMI's ipmi-oem tool before version 1.6.17High
- Cocos AI - attested TLS (aTLS) on AMD SEV-SNP and Intel TDX: The attested-TLS implementation is vulnerable to a relayCVE-2026-33697 · Cocos AI - attested TLS (aTLS) on AMD SEV-SNP and Intel TDXHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.