Known vulnerabilities in Enterprise SONiC - page 3

Vendor: Dell
Software CPE: cpe:2.3:a:dell:enterprise_sonic:*:*:*:*:*:*:*:*
Total vulnerabilities: 105
Public exploits: 10
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Enterprise SONiC Enterprise SONiC is affected by 105 known vulnerabilities: 16 high, 52 medium, 37 low Critical High Medium Low

Vulnerabilities (105)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU87685 - Resource exhaustion
CVE-2024-0450
CWE-400 Medium
No
No
4.2.1 21.03.2024 SB2024032107
SB2024032110
SB2024040848
and 80 more
#VU87185 - UNIX Symbolic Link (Symlink) Following
CVE-2023-6597
CWE-61 Low
No
No
4.2.1 07.03.2024 SB2024030718
SB2024030726
SB2024030727
and 88 more
#VU85765 - Improper Privilege Management
CVE-2023-7090
CWE-269 Low
No
No
4.2.1 24.01.2024 SB2024012433
SB2024042354
SB2024061232
and 3 more
#VU84537 - Inadequate Encryption Strength
CVE-2023-48795
CWE-326 Low
Available
No
4.2.1 19.12.2023 SB2023121903
SB2023121905
SB2023121906
and 343 more
#VU84035 - Stack-based buffer overflow
CVE-2023-39804
CWE-121 High
No
No
4.2.1 11.12.2023 SB2023121103
SB2023121110
SB2024010972
and 16 more
#VU83900 - Exposure of sensitive information to an unauthorized actor
CVE-2023-46218
CWE-200 Low
No
No
4.2.1 06.12.2023 SB2023120612
SB2023120644
SB2023120661
and 87 more
#VU82077 - Resource exhaustion
CVE-2022-48564
CWE-400 Medium
No
No
4.2.1 17.10.2023 SB2023101707
SB20231123125
SB2023112746
and 19 more
#VU81863 - External Control of File Name or Path
CVE-2023-38546
CWE-73 Low
No
No
4.2.1 11.10.2023 SB2023101129
SB2023101135
SB2023101149
and 125 more
#VU81728 - Resource exhaustion
CVE-2023-44487
CWE-400 High
Available
Exploited
4.2.1 10.10.2023 SB2023101023
SB2023101024
SB2023101037
and 651 more
#VU81627 - Out-of-bounds write
CVE-2023-4692
CWE-787 Low
No
No
4.2.1 05.10.2023 SB2023100511
SB2023100523
SB2023100703
and 27 more
#VU81434 - Integer overflow
CVE-2023-43787
CWE-190 Low
No
No
4.2.1 03.10.2023 SB2023100341
SB2023100346
SB2023100347
and 42 more
#VU81433 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2023-43786
CWE-835 Low
No
No
4.2.1 03.10.2023 SB2023100341
SB2023100346
SB2023100347
and 43 more
#VU81432 - Out-of-bounds read
CVE-2023-43785
CWE-125 Low
No
No
4.2.1 03.10.2023 SB2023100341
SB2023100347
SB2023100423
and 37 more
#VU78490 - Permissions, Privileges, and Access Controls
CVE-2023-34969
CWE-264 Low
No
No
4.2.1 21.07.2023 SB2023072119
SB2023072121
SB2023072122
and 61 more
#VU76238 - Expected Behavior Violation
CVE-2023-28322
CWE-440 Medium
No
No
4.2.1 17.05.2023 SB2023051752
SB2023051760
SB2023051761
and 88 more
#VU76237 - Improper Certificate Validation
CVE-2023-28321
CWE-295 Medium
No
No
4.2.1 17.05.2023 SB2023051752
SB2023051760
SB2023051761
and 99 more
#VU74197 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-28487
CWE-78 Low
No
No
4.2.1 30.03.2023 SB2023033028
SB2023033038
SB2023033039
and 28 more
#VU74196 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-28486
CWE-78 Low
No
No
4.2.1 30.03.2023 SB2023033028
SB2023033038
SB2023033039
and 31 more
#VU73827 - Improper input validation
CVE-2023-27534
CWE-20 Low
No
No
4.2.1 20.03.2023 SB2023032027
SB2023032028
SB2023032044
and 45 more
#VU58333 - Improper Privilege Management
CVE-2021-41617
CWE-269 Low
No
No
4.2.1 23.11.2021 SB2021092601
SB2021112330
SB2021120119
and 38 more


Showing elements 41 - 60 out of 105