Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. This is a critical severity vulnerability as it allows high privilege OS commands to be executed with a less privileged role; so Dell recommends customers to upgrade at the earliest opportunity.
The vulnerability results from improper sanitization of special characters in input data passed to operating system commands. An attacker with remote access and high but limited privileges can craft input containing malicious command sequences that will be interpreted and executed by the operating system. As a result, it is possible to execute commands with a privilege level higher than that assigned to the attacker's account, which also constitutes a privilege escalation.
An attacker can execute arbitrary system commands with elevated privileges, which may lead to complete takeover of the device, compromise of data confidentiality and integrity, and disruption of system availability.
Dell recommends updating the system to a version without the vulnerability as soon as possible. Detailed information about available patches is available in the security bulletin DSA-2024-449 at: https://www.dell.com/support/kbdoc/en-us/000245655/dsa-2024-449-security-update-for-dell-enterprise-sonic-distribution-vulnerabilities
Dell Enterprise SONiC OS in versions 4.1.x and 4.2.x
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HDell Enterprise Sonic Distribution
OSDell4.1.0 – 4.1.6 (excl.)4.2.0 – 4.2.2 (excl.)
Related vulnerabilities
OS Command Injection w Dell Enterprise SONiC OS 4.1.x i 4.2.x
Dell Enterprise SONiC OS — pominięcie krytycznego kroku uwierzytelnienia
Podatność improper input validation w Dell Enterprise SONiC — eskalacja uprawnień
Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Inser...
Dell Enterprise SONiC OS, 3.5.3, 4.0.0, 4.0.1, 4.0.2, contains an "Uncontrolled Resource Consumption vulnerab...