First published: Thu Feb 15 2024(Updated: )
Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A remote unauthenticated attacker could potentially exploit this vulnerability leading to information disclosure and a possible Denial of Service when a huge number of requests are sent to the switch. This is a high severity vulnerability as it allows an attacker to view sensitive data. Dell recommends customers to upgrade at the earliest opportunity.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell OS10 Networking Switches | >10.5.2 | |
Dell SmartFabric OS10 | >=10.5.2.0<10.5.2.12 | |
Dell SmartFabric OS10 | >=10.5.3.0<10.5.3.8 | |
Dell SmartFabric OS10 | >=10.5.4.0<10.5.4.8 | |
Dell SmartFabric OS10 | =10.5.5.0 | |
Dell SmartFabric OS10 | =10.5.5.1 | |
Dell SmartFabric OS10 | =10.5.5.2 | |
Dell SmartFabric OS10 | =10.5.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28078 is classified as a high severity vulnerability due to the potential for information disclosure and denial of service.
To remediate CVE-2023-28078, upgrade your Dell OS10 Networking Switches to the latest software version that addresses the vulnerability.
CVE-2023-28078 affects Dell OS10 Networking Switches running version 10.5.2.x and above with VLT configured.
CVE-2023-28078 allows a remote unauthenticated attacker to perform potential information disclosure and denial of service.
The underlying issue of CVE-2023-28078 is a vulnerability with zeroMQ when VLT is configured on affected switch models.