DSA-2024-376: Security Update for Dell Networking OS10 Vulnerability
Resumen: Dell Networking OS10 remediation is available for a security vulnerability that could be exploited by malicious users to compromise the affected system.
Este artículo se aplica a
Este artículo no se aplica a
Este artículo no está vinculado a ningún producto específico.
No se identifican todas las versiones del producto en este artículo.
Impacto
High
Detalles
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-38486 | Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
7.5 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2024-39585 | Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Password vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Client-side request forgery and Information disclosure. | 7.9 | CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-38486 | Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
7.5 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2024-39585 | Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Password vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Client-side request forgery and Information disclosure. | 7.9 | CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:H |
Corrección y productos afectados
| Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|
| Dell Networking OS10 | 10.5.6.x | 10.5.6.4 | SmartFabric OS10 downloads page |
| Dell Networking OS10 | 10.5.5.4 through 10.5.5.10 | 10.5.5.11 | SmartFabric OS10 downloads page |
| Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|
| Dell Networking OS10 | 10.5.6.x | 10.5.6.4 | SmartFabric OS10 downloads page |
| Dell Networking OS10 | 10.5.5.4 through 10.5.5.10 | 10.5.5.11 | SmartFabric OS10 downloads page |
- SmartFabric OS10 downloads are also available from your Dell Digital Locker.
- The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
NOTE:
- CVE-2024-38486 and CVE-2024-39585 are applicable to Switch Fabric Mode (SFS) only on OS10 platforms.
- OS10 is not vulnerable when operating in full switch mode.
- For MX setups, the CVEs apply to both full switch and SFS modes.
Historial de revisiones
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2024-09-05 | Initial Release |
| 2.0 | 2024-09-16 | Added CVE-2024-39585 |
| 3.0 | 2024-10-14 | Added a note to the additional information section |
Reconocimientos
Dell would like to thank n3k From TIANGONG Team of Legendsec at QI-ANXIN Group for reporting this issue.
Información relacionada
Descargo de responsabilidad
Productos afectados
SmartFabric OS10 SoftwarePropiedades del artículo
Número del artículo: 000228355
Tipo de artículo: Dell Security Advisory
Última modificación: 14 oct 2024
Encuentre respuestas a sus preguntas de otros usuarios de Dell
Servicios de soporte
Compruebe si el dispositivo está cubierto por los servicios de soporte.