First published: Thu Feb 15 2024(Updated: )
Dell OS10 Networking Switches running 10.5.2.x and above contain an OS command injection vulnerability when using remote user authentication. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands and possible system takeover. This is a critical vulnerability as it allows an attacker to cause severe damage. Dell recommends customers to upgrade at the earliest opportunity.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell OS10 Networking Switches | >10.5.2 | |
Dell SmartFabric OS10 | >=10.5.2.0<10.5.2.12 | |
Dell SmartFabric OS10 | >=10.5.3.0<10.5.3.8 | |
Dell SmartFabric OS10 | >=10.5.4.0<10.5.4.8 | |
Dell SmartFabric OS10 | =10.5.5.0 | |
Dell SmartFabric OS10 | =10.5.5.1 | |
Dell SmartFabric OS10 | =10.5.5.2 | |
Dell SmartFabric OS10 | =10.5.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-32462 is considered a high severity vulnerability due to its potential for arbitrary OS command execution.
To mitigate CVE-2023-32462, update Dell OS10 Networking Switches to the latest firmware version that addresses this vulnerability.
CVE-2023-32462 affects Dell OS10 Networking Switches running versions 10.5.2.x and above.
CVE-2023-32462 is an OS command injection vulnerability that can be exploited by unauthenticated remote attackers.
Exploitation of CVE-2023-32462 could lead to the execution of arbitrary commands and potential system takeover.