Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. This is a critical severity vulnerability so Dell recommends customers to upgrade at the earliest opportunity.
The vulnerability results from an error in the implementation of the authentication process — it lacks a critical step that should verify user identity before granting access. An attacker remotely, without having an account or password, can in certain circumstances (high attack complexity) bypass the protection mechanisms of the SONiC operating system. Successful exploitation of the vulnerability leads to a breach of security boundaries (scope changed), which indicates the possibility of impact beyond the direct component.
An attacker can bypass authentication mechanisms and system protection, which according to the CVSS vector results in complete loss of confidentiality, integrity, and availability of the attacked system. In practice, this means the possibility of taking control of an enterprise-class network device.
Dell recommends updating the system to a patched version as soon as possible. Detailed information about available patches and fixed versions can be found in the security bulletin DSA-2024-449 available at: https://www.dell.com/support/kbdoc/en-us/000245655/dsa-2024-449-security-update-for-dell-enterprise-sonic-distribution-vulnerabilities
Dell Enterprise SONiC OS in versions 4.1.x and 4.2.x
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HDell Enterprise Sonic Distribution
OSDell4.1.0 – 4.1.6 (excl.)4.2.0 – 4.2.2 (excl.)
Related vulnerabilities
OS Command Injection w Dell Enterprise SONiC OS 4.1.x i 4.2.x
OS Command Injection w Dell Enterprise SONiC OS (wersje 4.1.x, 4.2.x)
Podatność improper input validation w Dell Enterprise SONiC — eskalacja uprawnień
Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Inser...
Dell Enterprise SONiC OS, 3.5.3, 4.0.0, 4.0.1, 4.0.2, contains an "Uncontrolled Resource Consumption vulnerab...