CVE-2024-45765: OS Command Injection
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. This is a critical severity vulnerability as it allows high privilege OS commands to be executed with a less privileged role; so Dell recommends customers to upgrade at the earliest opportunity.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45765?
CVE-2024-45765 is classified as a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2024-45765?
To fix CVE-2024-45765, update Dell Enterprise SONiC OS to version 4.1.6 or 4.2.2 or later.
What types of systems are affected by CVE-2024-45765?
CVE-2024-45765 affects Dell Enterprise SONiC OS versions 4.1.x and 4.2.x.
Who can exploit CVE-2024-45765?
CVE-2024-45765 can be exploited by a high privileged attacker with remote access to the system.
What could happen if CVE-2024-45765 is exploited?
If exploited, CVE-2024-45765 could lead to unauthorized command execution on the affected system.