DSA-2024-376: Security Update for Dell Networking OS10 Vulnerability

Resumen: Dell Networking OS10 remediation is available for a security vulnerability that could be exploited by malicious users to compromise the affected system.

Este artículo se aplica a Este artículo no se aplica a Este artículo no está vinculado a ningún producto específico. No se identifican todas las versiones del producto en este artículo.

Impacto

High

Detalles

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2024-38486 Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
 
7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2024-39585 Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Password vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Client-side request forgery and Information disclosure. 7.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2024-38486 Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
 
7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2024-39585 Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Password vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Client-side request forgery and Information disclosure. 7.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies recomienda que todos los clientes tengan en cuenta tanto la puntuación base como cualquier otra puntuación ambiental y temporal relevante que pueda afectar la posible gravedad asociada con la vulnerabilidad de seguridad en particular.

Corrección y productos afectados

Product Affected Versions Remediated Versions Link
Dell Networking OS10 10.5.6.x 10.5.6.4 SmartFabric OS10 downloads page
Dell Networking OS10 10.5.5.4 through 10.5.5.10 10.5.5.11 SmartFabric OS10 downloads page
Product Affected Versions Remediated Versions Link
Dell Networking OS10 10.5.6.x 10.5.6.4 SmartFabric OS10 downloads page
Dell Networking OS10 10.5.5.4 through 10.5.5.10 10.5.5.11 SmartFabric OS10 downloads page
  • SmartFabric OS10 downloads are also available from your Dell Digital Locker.
  • The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
NOTE:
  • CVE-2024-38486 and CVE-2024-39585 are applicable to Switch Fabric Mode (SFS) only on OS10 platforms. 
  • OS10 is not vulnerable when operating in full switch mode.
  • For MX setups, the CVEs apply to both full switch and SFS modes.

Historial de revisiones

RevisionDateDescription
1.02024-09-05Initial Release
2.02024-09-16Added CVE-2024-39585
3.02024-10-14Added a note to the additional information section

Reconocimientos

Dell would like to thank n3k From TIANGONG Team of Legendsec at QI-ANXIN Group for reporting this issue.

Información relacionada

Productos afectados

SmartFabric OS10 Software
Propiedades del artículo
Número del artículo: 000228355
Tipo de artículo: Dell Security Advisory
Última modificación: 14 oct 2024
Encuentre respuestas a sus preguntas de otros usuarios de Dell
Servicios de soporte
Compruebe si el dispositivo está cubierto por los servicios de soporte.