216.73.217.22

CVE-2025-23374

· Published 30/01/2025 05:15 · Modified 07/02/2025 20:09

Labels: CVE-2025-23374 2025-01-30CVE-2025-23374CWE-532[email protected]

Essential information

Published
30/01/2025 05:15
Modified
07/02/2025 20:09
Author
Creator
CVSS
8.0 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
dell / enterprise sonic distribution cpe:2.3:o:dell:enterprise_sonic_distribution:*:*:*:*:*:*:*:*
dell / enterprise sonic distribution cpe:2.3:o:dell:enterprise_sonic_distribution:4.4.0:*:*:*:*:*:*:*

References