Known vulnerabilities in Enterprise SONiC

Vendor: Dell
Software CPE: cpe:2.3:a:dell:enterprise_sonic:*:*:*:*:*:*:*:*
Total vulnerabilities: 105
Public exploits: 10
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Enterprise SONiC Enterprise SONiC is affected by 105 known vulnerabilities: 16 high, 52 medium, 37 low Critical High Medium Low

Vulnerabilities (105)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU106269 - Information Exposure Through Log Files
CVE-2025-23374
CWE-532 Low
No
No
4.2.3, 4.4.1 31.03.2025 SB2025033122
#VU101850 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2024-31949
CWE-835 Medium
No
No
4.4.1 19.12.2024 SB2024121927
SB2024122019
SB2025021864
#VU97120 - Improper input validation
CVE-2024-44070
CWE-20 Medium
No
No
4.4.1 11.09.2024 SB2024091102
SB2024091103
SB2024091110
and 8 more
#VU96899 - Integer overflow
CVE-2024-45492
CWE-190 High
No
No
4.4.1 05.09.2024 SB20240905100
SB20240905101
SB20240905102
and 108 more
#VU96898 - Integer overflow
CVE-2024-45491
CWE-190 High
No
No
4.4.1 05.09.2024 SB20240905100
SB20240905101
SB20240905102
and 106 more
#VU96897 - Buffer Underwrite ('Buffer Underflow')
CVE-2024-45490
CWE-124 High
No
No
4.4.1 05.09.2024 SB20240905100
SB20240905101
SB20240905102
and 113 more
#VU90721 - Memory corruption
CVE-2024-31948
CWE-119 Medium
No
No
4.4.1 03.06.2024 SB2024060324
SB2024060326
SB2024060327
and 5 more
#VU88144 - Improper input validation
CVE-2024-28182
CWE-20 Medium
No
No
4.4.1 04.04.2024 SB2024040442
SB2024040443
SB2024040444
and 124 more
#VU86230 - Resource exhaustion
CVE-2023-52425
CWE-400 Medium
No
No
4.4.1 07.02.2024 SB2024020750
SB2024020754
SB2024020765
and 120 more
#VU84985 - Out-of-bounds read
CVE-2023-7104
CWE-125 Medium
No
No
4.4.1 04.01.2024 SB2024010417
SB2024010420
SB2024010516
and 108 more
#VU82902 - Improper input validation
CVE-2023-46753
CWE-20 Medium
No
No
4.4.1 07.11.2023 SB20231107126
SB2023111547
SB2023111548
and 9 more
#VU82901 - Improper input validation
CVE-2023-46752
CWE-20 Medium
No
No
4.4.1 07.11.2023 SB20231107126
SB2023111548
SB2023111715
and 8 more
#VU82900 - Improper input validation
CVE-2023-47235
CWE-20 Medium
No
No
4.4.1 07.11.2023 SB20231107126
SB2023112144
SB2023120658
and 10 more
#VU82899 - Improper input validation
CVE-2023-47234
CWE-20 Medium
No
No
4.4.1 07.11.2023 SB20231107126
SB2023112144
SB2023120658
and 10 more
#VU71379 - Incorrect Regular Expression
CVE-2022-40897
CWE-185 Medium
No
No
4.4.1 20.01.2023 SB2023012008
SB2023012015
SB2023012016
and 99 more
#VU67279 - Use After Free
CVE-2022-37035
CWE-416 High
No
No
4.4.1 13.09.2022 SB2022091376
SB2022101848
SB2024060533
and 2 more
#VU66813 - NULL Pointer Dereference
CVE-2022-2309
CWE-476 Medium
No
No
4.4.1 29.08.2022 SB2022082928
SB2022082929
SB2022082930
and 28 more
#VU66123 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2016-3709
CWE-79 Medium
No
No
4.4.1 05.08.2022 SB2022080507
SB2022080510
SB2022080808
and 43 more
#VU64075 - Out-of-bounds write
CVE-2022-1304
CWE-787 Low
No
No
4.4.1 08.06.2022 SB2022060814
SB2022060815
SB2022060830
and 66 more
#VU63627 - Memory corruption
CVE-2021-36690
CWE-119 Low
No
No
4.4.1 25.05.2022 SB2022050533
SB2022071831
SB2022092034
and 16 more


Showing elements 1 - 20 out of 105