Critical
Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
---|---|---|---|
CVE-2023-28078 | Dell OS10 Networking Switches, versions 10.5.2.x and above, when configured with VLT or Smart Fabric mode contains an improper restriction of communication channel to intended endpoints vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to information disclosure and a possible denial of service. This is a critical severity vulnerability as it allows an attacker to view sensitive data. Dell recommends customers to upgrade at the earliest opportunity. | 9.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
CVE-2023-32462 | Dell OS10 Networking Switches, versions 10.5.2.x and above, contain an OS command injection vulnerability when using remote user authentication. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands and possible system take over. This is a critical vulnerability as it allows an attacker to cause severe damage. Dell recommends customers to upgrade at the earliest opportunity. | 9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
---|---|---|---|
CVE-2023-28078 | Dell OS10 Networking Switches, versions 10.5.2.x and above, when configured with VLT or Smart Fabric mode contains an improper restriction of communication channel to intended endpoints vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to information disclosure and a possible denial of service. This is a critical severity vulnerability as it allows an attacker to view sensitive data. Dell recommends customers to upgrade at the earliest opportunity. | 9.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
CVE-2023-32462 | Dell OS10 Networking Switches, versions 10.5.2.x and above, contain an OS command injection vulnerability when using remote user authentication. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands and possible system take over. This is a critical vulnerability as it allows an attacker to cause severe damage. Dell recommends customers to upgrade at the earliest opportunity. | 9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
---|---|---|---|---|
Dell EMC Networking MX5108n | Dell Networking MX SmartFabric OS10 | Versions prior to 10.5.4.9 | Version 10.5.4.9 or later | https://www.dell.com/support/home/product-support/product/poweredge-mx7000/drivers |
Dell EMC Networking MX5108n | Dell Networking MX SmartFabric OS10 | Versions prior to 10.5.5.4 | Version 10.5.5.4 or later | https://www.dell.com/support/home/product-support/product/poweredge-mx7000/drivers |
Dell EMC Networking MX9116n | Dell Networking MX SmartFabric OS10 | Versions prior to 10.5.4.9 | Version 10.5.4.9 or later | https://www.dell.com/support/home/product-support/product/poweredge-mx7000/drivers |
Dell EMC Networking MX9116n | Dell Networking MX SmartFabric OS10 | Versions prior to 10.5.5.4 | 10.5.5.4 or later | https://www.dell.com/support/home/product-support/product/poweredge-mx7000/drivers |
Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
---|---|---|---|---|
Dell EMC Networking MX5108n | Dell Networking MX SmartFabric OS10 | Versions prior to 10.5.4.9 | Version 10.5.4.9 or later | https://www.dell.com/support/home/product-support/product/poweredge-mx7000/drivers |
Dell EMC Networking MX5108n | Dell Networking MX SmartFabric OS10 | Versions prior to 10.5.5.4 | Version 10.5.5.4 or later | https://www.dell.com/support/home/product-support/product/poweredge-mx7000/drivers |
Dell EMC Networking MX9116n | Dell Networking MX SmartFabric OS10 | Versions prior to 10.5.4.9 | Version 10.5.4.9 or later | https://www.dell.com/support/home/product-support/product/poweredge-mx7000/drivers |
Dell EMC Networking MX9116n | Dell Networking MX SmartFabric OS10 | Versions prior to 10.5.5.4 | 10.5.5.4 or later | https://www.dell.com/support/home/product-support/product/poweredge-mx7000/drivers |
Revision | Date | Description |
---|---|---|
1.0 | 2023-08-07 | Initial release |
CVE-2023-28078: Dell Technologies would like to thank Rafael Schaefer, ERNW Enno Rey Netzwerke GmbH for reporting this issue.