CVE-2023-24574: High severity dell enterprise sonic os vulnerability
Dell Enterprise SONiC OS, 3.5.3, 4.0.0, 4.0.1, 4.0.2, contains an "Uncontrolled Resource Consumption vulnerability" in authentication component. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to uncontrolled resource consumption by creating permanent home directories for unauthenticated users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24574?
CVE-2023-24574 is classified as a high-severity uncontrolled resource consumption vulnerability.
How do I fix CVE-2023-24574?
To fix CVE-2023-24574, upgrade to a fixed version of Dell Enterprise SONiC OS beyond 4.0.3.
Which versions of Dell Enterprise SONiC OS are affected by CVE-2023-24574?
CVE-2023-24574 affects Dell Enterprise SONiC OS versions 3.5.3, 4.0.0, 4.0.1, and 4.0.2.
Can CVE-2023-24574 be exploited remotely?
Yes, CVE-2023-24574 can be exploited remotely by an unauthenticated attacker.
What components are involved in CVE-2023-24574?
CVE-2023-24574 involves the authentication component of the Dell Enterprise SONiC OS.