Database/Firmware, BMC & network fabric
Dell Enterprise SONiC (privilege boundary in CLI): High-privilege OS commands can be run by users holding less
CVE-2024-45765Firmware, BMC & network fabricDSA-2024-449curated
Impact
High-privilege OS commands can be run by users holding less privileged roles. Whatever role separation you built for your NOC — read-only, operator, admin — does not hold on the switch. Relevant to any operator who gives tenants or contractors scoped switch access.
Who can reach it
Authenticated user with a low-privilege SONiC role.
What to do
NOS image upgrade and reboot per switch. Until then, do not issue low-privilege SONiC accounts to anyone you would not give admin, because the distinction is not enforced.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.