PT-2024-31758 · Dell · Dell Enterprise Sonic Os

N3K

·

Published

2024-11-08

·

Updated

2024-11-13

·

CVE-2024-45765

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Dell Enterprise SONiC OS versions 4.1.x through 4.2.x
Description: The issue is related to an Improper Neutralization of Special Elements used in an OS Command, also known as 'OS Command Injection'. This allows a high privileged attacker with remote access to potentially execute commands. The severity of this issue is critical, as it enables the execution of high privilege OS commands with a less privileged role.
Recommendations: For Dell Enterprise SONiC OS versions 4.1.x through 4.2.x, upgrade at the earliest opportunity to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the system to minimize the risk of exploitation.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-45765

Affected Products

Dell Enterprise Sonic Os