CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2023-28078

CVSS 9.1v3.1pub. 2024-02-15upd. 2025-01-23

Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A remote unauthenticated attacker could potentially exploit this vulnerability leading to information disclosure and a possible Denial of Service when a huge number of requests are sent to the switch. This is a high severity vulnerability as it allows an attacker to view sensitive data. Dell recommends customers to upgrade at the earliest opportunity.

🤖 AI Analysis
How it works

The vulnerability stems from improper handling of communication by the zeroMQ component, activated when the VLT (Virtual Link Trunking) feature is configured on the switch. A remote attacker without any privileges can send a large number of requests to the device, leading to disclosure of sensitive information and potential exhaustion of switch resources resulting in denial of service. The lack of user interaction requirement and no need for permissions makes the exploit particularly easy to perform from the network.

Impact

An attacker can gain access to sensitive data processed by the switch (confidentiality breach) and cause its unavailability by sending a large number of requests (Denial of Service).

Mitigation & patch

Dell recommends updating the software as soon as possible to a non-vulnerable version. Apply patches available from the manufacturer according to references (DSA-2023-124, available at: https://www.dell.com/support/kbdoc/en-us/000216584/dsa-2023-124-security-update-for-dell-smartfabric-os10-multiple-vulnerabilities). Until the patch is implemented, it is recommended to consider disabling or restricting network access to zeroMQ ports on devices with VLT.

Who is affected

Dell SmartFabric OS10 Networking Switches versions 10.5.2.x and later, with VLT (Virtual Link Trunking) configuration enabled.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
  • Dell Smartfabric Os10

    OS
    Dell
    10.5.5.010.5.5.110.5.5.210.5.5.310.5.3.0 – 10.5.3.8 (excl.)10.5.4.0 – 10.5.4.8 (excl.)10.5.2.0 – 10.5.2.12 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth BypassDoS
CWE
References

Related vulnerabilities

CVE-2023-32462CRITICAL9.8PL ✓same product

Dell SmartFabric OS10 — command injection przy zdalnym uwierzytelnianiu

CVE-2025-46427HIGH8.8same product

Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elem...

CVE-2025-46428HIGH8.8same product

Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Ele...

CVE-2024-48831HIGH8.4same product

Dell SmartFabric OS10 Software, version(s) 10.5.6.x, contain(s) a Use of Hard-coded Password vulnerability. An...

CVE-2024-48013HIGH8.8same product

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Execution wit...