DSA-2024-425: Security Update for Dell Networking OS10 Vulnerabilities
Summary: Dell Networking OS10 remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
High
Details
| Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
| CVE-2024-48837 |
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.
|
7.8 |
|
| CVE-2024-48838 |
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a Files or Directories Accessible to External Parties vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
|
3.3 |
|
| CVE-2024-49557 |
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
|
7.8 |
|
| CVE-2024-49558 |
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
|
7.8 |
|
| CVE-2024-49560 |
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a command injection vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution. |
7.8 |
| Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
| CVE-2024-48837 |
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.
|
7.8 |
|
| CVE-2024-48838 |
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a Files or Directories Accessible to External Parties vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
|
3.3 |
|
| CVE-2024-49557 |
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
|
7.8 |
|
| CVE-2024-49558 |
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
|
7.8 |
|
| CVE-2024-49560 |
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a command injection vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution. |
7.8 |
Affected Products & Remediation
| Product |
Affected Versions |
Remediated Versions |
Link |
| Dell Networking OS10 |
Version 10.5.6.x |
Version 10.5.6.6 |
|
| Dell Networking OS10 |
Version 10.5.5.x |
Version 10.5.5.12 |
|
| Dell Networking OS10 |
Version 10.5.4.x |
Version 10.5.4.13 |
| Product |
Affected Versions |
Remediated Versions |
Link |
| Dell Networking OS10 |
Version 10.5.6.x |
Version 10.5.6.6 |
|
| Dell Networking OS10 |
Version 10.5.5.x |
Version 10.5.5.12 |
|
| Dell Networking OS10 |
Version 10.5.4.x |
Version 10.5.4.13 |
- SmartFabric OS10 downloads are also available from your Dell Digital Locker.
- The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2024-11-11 |
Initial Release |
|
2.0 |
2024-11-22 |
Formatting changes only. No changes to content. |
Acknowledgements
- CVE-2024-48837, CVE-2024-48838, CVE-2024-49557, CVE-2024-49558: Dell would like to thank n3k From TIANGONG Team of Legendsec at QI-ANXIN Group for reporting these issues.
- CVE-2024-49560: Dell would like to thank zzcentury from Ubisectech Sirius Team for reporting this issue.