Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-41588 | Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. This is a critical severity vulnerability as it allows high privilege OS commands to be executed with a less privileged role; so Dell recommends customers to upgrade at the earliest opportunity. |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 13 Nov 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dell enterprise Sonic Distribution
|
|
| CPEs | cpe:2.3:o:dell:enterprise_sonic_distribution:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dell enterprise Sonic Distribution
|
Fri, 08 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dell
Dell enterprise Sonic Os |
|
| CPEs | cpe:2.3:o:dell:enterprise_sonic_os:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dell
Dell enterprise Sonic Os |
|
| Metrics |
ssvc
|
Fri, 08 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. This is a critical severity vulnerability as it allows high privilege OS commands to be executed with a less privileged role; so Dell recommends customers to upgrade at the earliest opportunity. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-11-08T17:03:50.218Z
Reserved: 2024-09-06T06:30:30.481Z
Link: CVE-2024-45765
Updated: 2024-11-08T17:03:11.350Z
Status : Analyzed
Published: 2024-11-08T16:15:23.350
Modified: 2024-11-13T19:06:45.377
Link: CVE-2024-45765
No data.
OpenCVE Enrichment
No data.
EUVD