Vulnerability Description
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. This is a critical severity vulnerability as it allows high privilege OS commands to be executed with a less privileged role; so Dell recommends customers to upgrade at the earliest opportunity.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Enterprise Sonic Distribution | >= 4.1.0, < 4.1.6 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-45765?
CVE-2024-45765 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker wi...
How severe is CVE-2024-45765?
CVE-2024-45765 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-45765?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Enterprise Sonic Distribution.