Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-28078

Опубликовано: 15 фев. 2024
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A remote unauthenticated attacker could potentially exploit this vulnerability leading to information disclosure and a possible Denial of Service when a huge number of requests are sent to the switch. This is a high severity vulnerability as it allows an attacker to view sensitive data. Dell recommends customers to upgrade at the earliest opportunity.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:dell:smartfabric_os10:*:*:*:*:*:*:*:*
Версия от 10.5.2.0 (включая) до 10.5.2.12 (исключая)
cpe:2.3:o:dell:smartfabric_os10:*:*:*:*:*:*:*:*
Версия от 10.5.3.0 (включая) до 10.5.3.8 (исключая)
cpe:2.3:o:dell:smartfabric_os10:*:*:*:*:*:*:*:*
Версия от 10.5.4.0 (включая) до 10.5.4.8 (исключая)
cpe:2.3:o:dell:smartfabric_os10:10.5.5.0:*:*:*:*:*:*:*
cpe:2.3:o:dell:smartfabric_os10:10.5.5.1:*:*:*:*:*:*:*
cpe:2.3:o:dell:smartfabric_os10:10.5.5.2:*:*:*:*:*:*:*
cpe:2.3:o:dell:smartfabric_os10:10.5.5.3:*:*:*:*:*:*:*

EPSS

Процентиль: 58%
0.0037
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-923
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 9.1
github
почти 2 года назад

Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A remote unauthenticated attacker could potentially exploit this vulnerability leading to information disclosure and a possible Denial of Service when a huge number of requests are sent to the switch. This is a high severity vulnerability as it allows an attacker to view sensitive data. Dell recommends customers to upgrade at the earliest opportunity.

EPSS

Процентиль: 58%
0.0037
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-923
NVD-CWE-noinfo