Known vulnerabilities in Dell Enterprise SONiC Distribution

Vendor: Dell
Software CPE: cpe:2.3:a:dell:dell_enterprise_sonic_distribution:*:*:*:*:*:*:*:*
Total vulnerabilities: 37
Public exploits: 3
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Dell Enterprise SONiC Distribution Dell Enterprise SONiC Distribution is affected by 37 known vulnerabilities: 5 high, 17 medium, 15 low Critical High Medium Low

Vulnerabilities (37)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU143641 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-34714
CWE-78 Low
No
No
4.6.0 17.08.2026 SB2026081760
SB2026081761
SB2026081762
and 6 more
#VU128473 - Improper input validation
CVE-2026-35386
CWE-20 Low
No
No
4.6.0 29.04.2026 SB2026042988
SB2026042990
SB2026042992
and 16 more
#VU128474 - Improper Access Control
CVE-2026-35414
CWE-284 Low
No
No
4.6.0 29.04.2026 SB2026042988
SB2026042990
SB2026042992
and 24 more
#VU128475 - Improper Privilege Management
CVE-2026-35385
CWE-269 Low
No
No
4.6.0 29.04.2026 SB2026042988
SB2026042990
SB2026042992
and 30 more
#VU128476 - Improper Access Control
CVE-2026-35387
CWE-284 Low
No
No
4.6.0 29.04.2026 SB2026042988
SB2026042990
SB2026042992
and 17 more
#VU128477 - Improper Authorization
CVE-2026-35388
CWE-285 Low
No
No
4.6.0 29.04.2026 SB2026042988
SB2026042990
SB2026042992
and 19 more
#VU118176 - Resource exhaustion
CVE-2025-64329
CWE-400 Low
No
No
4.6.0 07.11.2025 SB2025110610
SB2025111276
SB2025112826
and 12 more
#VU118141 - Incorrect Default Permissions
CVE-2024-25621
CWE-276 Low
No
No
4.6.0 06.11.2025 SB2025110610
SB2025111276
SB2025112826
and 17 more
#VU116641 - Improper Authentication
CVE-2025-46818
CWE-287 Medium
Available
No
4.6.0 07.10.2025 SB2025100706
SB2025100709
SB2025100710
and 39 more
#VU116640 - Out-of-bounds read
CVE-2025-46819
CWE-125 Medium
Available
No
4.6.0 07.10.2025 SB2025100706
SB2025100709
SB2025100710
and 39 more
#VU116639 - Integer overflow
CVE-2025-46817
CWE-190 High
Available
No
4.6.0 07.10.2025 SB2025100706
SB2025100709
SB2025100710
and 46 more
#VU100566 - Off-by-one Error
CVE-2024-52533
CWE-193 High
No
No
4.4.2 15.11.2024 SB20241115147
SB20241115148
SB20241115149
and 71 more
#VU94533 - Improper input validation
CVE-2024-0397
CWE-20 Low
No
No
4.4.2 18.07.2024 SB2024071850
SB2024080209
SB2024080211
and 33 more
#VU75604 - Improper Certificate Validation
CVE-2023-31484
CWE-295 Medium
No
No
4.4.2 01.05.2023 SB2023050116
SB2023052927
SB2023060526
and 39 more
#VU67760 - Type conversion
CVE-2020-10735
CWE-704 Medium
No
No
4.4.2 29.09.2022 SB2022092968
SB2022092970
SB2022093032
and 86 more
#VU64573 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2015-20107
CWE-78 High
No
No
4.4.2 22.06.2022 SB2022062206
SB2022062207
SB2022062436
and 85 more
#VU61681 - Server-Side Request Forgery (SSRF)
CVE-2021-4189
CWE-918 Medium
No
No
4.4.2 29.03.2022 SB2022032904
SB2022032905
SB2022032907
and 42 more
#VU60098 - Improper input validation
CVE-2021-3426
CWE-20 Medium
No
No
4.4.2 27.01.2022 SB2022012753
SB2022032905
SB2022032907
and 34 more
#VU59089 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2021-3737
CWE-835 Low
No
No
4.4.2 22.12.2021 SB2021122214
SB2022050235
SB2022051138
and 58 more
#VU58295 - Resource Management Errors
CVE-2021-3733
CWE-399 Low
No
No
4.4.2 23.11.2021 SB2021112309
SB2021122214
SB2022050235
and 41 more


Showing elements 1 - 20 out of 37