GPU VulnDB

Database/Firmware, BMC & network fabric

Dell Enterprise SONiC OS (input validation): Improper input validation on Dell Networking switches running Enterprise

CVE-2023-32484Firmware, BMC & network fabriccurated

Impact

Improper input validation on Dell Networking switches running Enterprise SONiC, exploitable by a remote unauthenticated attacker. Affects 4.1.0, 4.0.5, 3.5.4 and below — i.e. essentially every SONiC release before the 2024 hardening pass. If you bought Dell switches with SONiC for a cost-optimised GPU buildout in 2022-2023 and have not touched the NOS since, this is live.

Who can reach it

Unauthenticated, remote to the switch.

What to do

NOS image upgrade and switch reboot. On SONiC that is a full image install, so the switch is down for minutes — stage across MLAG pairs. Put SONiC management interfaces on an isolated OOB network as the standing control.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.