DSA-2025-057: Security Update for Dell Enterprise SONiC Distribution Vulnerability
Summary: Dell Enterprise SONiC remediation is available for a Insertion of Sensitive Information into Log File vulnerability that could be exploited by malicious users to compromise the affected system. ...
Impact
High
Details
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2025-23374 |
Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
8.0 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2025-23374 |
Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
8.0 |
Affected Products & Remediation
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell Enterprise SONiC Distribution |
Versions prior to 4.4.1 |
Version 4.4.1 or later |
|
|
Dell Enterprise SONiC Distribution |
Versions prior to 4.2.3 |
Version 4.2.3 or later |
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell Enterprise SONiC Distribution |
Versions prior to 4.4.1 |
Version 4.4.1 or later |
|
|
Dell Enterprise SONiC Distribution |
Versions prior to 4.2.3 |
Version 4.2.3 or later |
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2025-29-01 |
Initial Release |