PT-2025-4867 · Dell · Enterprise Sonic

Published

2025-01-29

·

Updated

2025-02-07

·

CVE-2025-23374

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell Networking Switches running Enterprise SONiC OS versions prior to 4.4.1 and 4.2.3
Description The issue concerns an Insertion of Sensitive Information into Log File, which could be exploited by a high privileged attacker with remote access, potentially leading to information exposure.
Recommendations For versions prior to 4.4.1, update to version 4.4.1 or later. For versions prior to 4.2.3, update to version 4.2.3 or later. As a temporary workaround, consider restricting access to log files to minimize the risk of exploitation.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

BDU:2025-11356
CVE-2025-23374

Affected Products

Enterprise Sonic