Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. This is a critical severity vulnerability so Dell recommends customers to upgrade at the earliest opportunity.
The vulnerability results from improper neutralization of special characters passed to operating system commands. A remote attacker with high privileges can prepare input data containing malicious sequences that the operating system will interpret as separate commands. Successful exploitation of the flaw leads to execution of arbitrary commands in the context of the device's operating system.
An attacker can execute arbitrary commands at the operating system level on the network device, which may lead to complete takeover of the device, violation of data confidentiality and integrity, and disruption of its availability.
Dell Enterprise SONiC OS should be updated as soon as possible to a version free from the vulnerability in accordance with the manufacturer's recommendations published in bulletin DSA-2024-449 available at: https://www.dell.com/support/kbdoc/en-us/000245655/dsa-2024-449-security-update-for-dell-enterprise-sonic-distribution-vulnerabilities
Dell Enterprise SONiC OS in versions 4.1.x and 4.2.x
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HDell Enterprise Sonic Distribution
OSDell4.1.0 – 4.1.6 (excl.)4.2.0 – 4.2.2 (excl.)
Related vulnerabilities
Dell Enterprise SONiC OS — pominięcie krytycznego kroku uwierzytelnienia
OS Command Injection w Dell Enterprise SONiC OS (wersje 4.1.x, 4.2.x)
Podatność improper input validation w Dell Enterprise SONiC — eskalacja uprawnień
Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Inser...
Dell Enterprise SONiC OS, 3.5.3, 4.0.0, 4.0.1, 4.0.2, contains an "Uncontrolled Resource Consumption vulnerab...