PT-2023-8984 · Dell · Enterprise Sonic

Published

2023-08-02

·

Updated

2024-02-20

·

CVE-2023-32484

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Dell Networking Switches running Enterprise SONiC versions 4.1.0, 4.0.5, 3.5.4 and below
Description The issue is related to an improper input validation vulnerability. A remote unauthenticated malicious user may exploit this vulnerability and escalate privileges up to the highest administrative level. This is a critical vulnerability affecting certain protocols.
Recommendations For versions 4.1.0, 4.0.5, 3.5.4 and below, upgrade to a newer version at the earliest opportunity to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-02847
CVE-2023-32484

Affected Products

Enterprise Sonic