GPU VulnDB

Database/Firmware, BMC & network fabric

Dell Enterprise SONiC OS 4.5.0 (SSH cryptographic key): The SSH cryptographic-key weakness recurring in Enterprise

CVE-2025-38741Firmware, BMC & network fabriccurated

Impact

The SSH cryptographic-key weakness recurring in Enterprise SONiC 4.5.0, three years after the same class was fixed in 4.0.x. For an operator the lesson is that SONiC host-key uniqueness is not something to assume from a version number — check it directly on every switch you deploy.

Who can reach it

Unauthenticated, remote against the switch's SSH service.

What to do

NOS image upgrade plus reboot, then regenerate host keys and refresh your automation's trust store. Consider adding a fleet-wide host-key uniqueness assertion to your provisioning tests.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.