Impact
High
Details
Proprietary Code CVE |
Description |
CVSS Base Score |
CVSS Vector String |
CVE-2022-344225 |
Dell Enterprise SONiC operating system 4.0.0 and 4.0.1 contain a cryptographic key vulnerability in SSH. An unauthenticated remote attacker may potentially exploit this vulnerability, leading to unauthorized access to communication. |
7.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Proprietary Code CVE |
Description |
CVSS Base Score |
CVSS Vector String |
CVE-2022-344225 |
Dell Enterprise SONiC operating system 4.0.0 and 4.0.1 contain a cryptographic key vulnerability in SSH. An unauthenticated remote attacker may potentially exploit this vulnerability, leading to unauthorized access to communication. |
7.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.
Product |
Affected Versions |
Updated Version |
Link to Update |
Dell Enterprise SONiC Distribution |
Versions 4.0.0 and 4.0.1 |
4.0.2 |
Link to update |
Product |
Affected Versions |
Updated Version |
Link to Update |
Dell Enterprise SONiC Distribution |
Versions 4.0.0 and 4.0.1 |
4.0.2 |
Link to update |
Workarounds & Mitigations
Delete installed SSH keys and restart SSHD service.
Revision History
Revision | Date | Description |
1.0 | 2022-09-15 | Initial Release |
Dell Security Advisories and Notices
Dell Vulnerability Response Policy
CVSS Scoring Guide
Products
Product Security Information