CVE-2023-28078

Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A remote unauthenticated attacker could potentially exploit this vulnerability leading to information disclosure and a possible Denial of Service when a huge number of requests are sent to the switch. This is a high severity vulnerability as it allows an attacker to view sensitive data. Dell recommends customers to upgrade at the earliest opportunity.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:dell:smartfabric_os10:10.5.5.1:*:*:*:*:*:*:*
cpe:2.3:o:dell:smartfabric_os10:10.5.5.2:*:*:*:*:*:*:*
cpe:2.3:o:dell:smartfabric_os10:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:smartfabric_os10:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:smartfabric_os10:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:smartfabric_os10:10.5.5.0:*:*:*:*:*:*:*
cpe:2.3:o:dell:smartfabric_os10:10.5.5.3:*:*:*:*:*:*:*

History

23 Jan 2025, 17:03

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000216584/dsa-2023-124-security-update-for-dell-smartfabric-os10-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000216584/dsa-2023-124-security-update-for-dell-smartfabric-os10-multiple-vulnerabilities - Vendor Advisory
CWE CWE-923 NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
First Time Dell
Dell smartfabric Os10
CPE cpe:2.3:o:dell:smartfabric_os10:10.5.5.3:*:*:*:*:*:*:*
cpe:2.3:o:dell:smartfabric_os10:10.5.5.1:*:*:*:*:*:*:*
cpe:2.3:o:dell:smartfabric_os10:10.5.5.0:*:*:*:*:*:*:*
cpe:2.3:o:dell:smartfabric_os10:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:smartfabric_os10:10.5.5.2:*:*:*:*:*:*:*

15 Feb 2024, 14:28

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-15 13:15

Updated : 2025-01-23 17:03


NVD link : CVE-2023-28078

Mitre link : CVE-2023-28078


JSON object : View

Products Affected

dell

  • smartfabric_os10