Database/Firmware, BMC & network fabric
Dell Enterprise SONiC OS 4.5.0 (SSH cryptographic key): The SSH cryptographic-key weakness recurring in Enterprise
Impact
The SSH cryptographic-key weakness recurring in Enterprise SONiC 4.5.0, three years after the same class was fixed in 4.0.x. For an operator the lesson is that SONiC host-key uniqueness is not something to assume from a version number — check it directly on every switch you deploy.
Who can reach it
Unauthenticated, remote against the switch's SSH service.
What to do
NOS image upgrade plus reboot, then regenerate host keys and refresh your automation's trust store. Consider adding a fleet-wide host-key uniqueness assertion to your provisioning tests.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.