Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A remote unauthenticated attacker could potentially exploit this vulnerability leading to information disclosure and a possible Denial of Service when a huge number of requests are sent to the switch. This is a high severity vulnerability as it allows an attacker to view sensitive data. Dell recommends customers to upgrade at the earliest opportunity.
The vulnerability stems from improper handling of communication by the zeroMQ component, activated when the VLT (Virtual Link Trunking) feature is configured on the switch. A remote attacker without any privileges can send a large number of requests to the device, leading to disclosure of sensitive information and potential exhaustion of switch resources resulting in denial of service. The lack of user interaction requirement and no need for permissions makes the exploit particularly easy to perform from the network.
An attacker can gain access to sensitive data processed by the switch (confidentiality breach) and cause its unavailability by sending a large number of requests (Denial of Service).
Dell recommends updating the software as soon as possible to a non-vulnerable version. Apply patches available from the manufacturer according to references (DSA-2023-124, available at: https://www.dell.com/support/kbdoc/en-us/000216584/dsa-2023-124-security-update-for-dell-smartfabric-os10-multiple-vulnerabilities). Until the patch is implemented, it is recommended to consider disabling or restricting network access to zeroMQ ports on devices with VLT.
Dell SmartFabric OS10 Networking Switches versions 10.5.2.x and later, with VLT (Virtual Link Trunking) configuration enabled.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HDell Smartfabric Os10
OSDell10.5.5.010.5.5.110.5.5.210.5.5.310.5.3.0 – 10.5.3.8 (excl.)10.5.4.0 – 10.5.4.8 (excl.)10.5.2.0 – 10.5.2.12 (excl.)
Related vulnerabilities
Dell SmartFabric OS10 — command injection przy zdalnym uwierzytelnianiu
Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elem...
Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Ele...
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, contain(s) a Use of Hard-coded Password vulnerability. An...
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Execution wit...