DSA-2025-023: Security Update for Dell Connectrix MDS Cisco Bootloader Vulnerability

Summary: Dell Connectrix MDS-Series remediation is available for the Bootloader that could be exploited by malicious users to compromise the affected system.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

Medium

Details

Third-party Component CVEs More Information
Bootloader CVE-2024-20397 CVE-2024-20397This hyperlink is taking you to a website outside of Dell Technologies.

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Product Software/Firmware Affected Versions Remediated Versions Link
Connectrix MDS-Series NX-OS Versions prior to 9.4(2) Versions 9.4(2a) or later https://www.dell.com/support/home/product-support/product/connectrix-mds-series-hardware/drivers
Product Software/Firmware Affected Versions Remediated Versions Link
Connectrix MDS-Series NX-OS Versions prior to 9.4(2) Versions 9.4(2a) or later https://www.dell.com/support/home/product-support/product/connectrix-mds-series-hardware/drivers

Workarounds & Mitigations

CVE ID Workaround and Mitigation
CVE-2024-20397

For Cisco MDS and Nexus standalone platforms, if the device was not previously upgraded by using the install all CLI command, the BIOS might not have been upgraded. Even if customers are running a fixed Cisco NX-OS Software release, they are advised to check the BIOS version and use the install all command to complete the BIOS upgrade, if applicable.

So even if the device is running the fixed release we recommend checking the actual BIOS version to be sure.

Revision History

RevisionDateDescription
1.02025-01-06Initial Release

Related Information

Affected Products

Connectrix MDS-9124V, Connectrix MDS-9132T, Connectrix MDS-9148S, Connectrix MDS-9148T, Connectrix MDS-9148V, Connectrix MDS-9220i, Connectrix MDS-9250i, Connectrix MDS-9396S, Connectrix MDS-9396S PSI, Connectrix MDS-9396T, Connectrix MDS-9396V , Connectrix MDS-9706, Connectrix MDS-9706-V2, Connectrix MDS-9710, Connectrix MDS-9710-V2, Connectrix MDS-9718, Connectrix MDS-9718-V3, Connectrix MDS-Series Hardware, Connectrix MDS 9132T, Connectrix MDS 9148S, Connectrix MDS 9148T, Connectrix MDS 9396S, Connectrix MDS 9396T ...
Article Properties
Article Number: 000261082
Article Type: Dell Security Advisory
Last Modified: 06 Jan 2025
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.