Dell Networking Switches Enterprise SONiC OS Insertion of Sensitive Information into Log File Vulnerability

Vulnerability

A vulnerability allowing the insertion of sensitive information into log files has been identified in Dell Networking Switches running Enterprise SONiC OS, versions prior to 4.4.1 and 4.2.3. This vulnerability could be exploited by a high-privileged attacker with remote access, leading to unauthorized information exposure.

Impact

Exploitation of this vulnerability could result in the unauthorized exposure of sensitive information.

Remediation

Users can update to version 4.4.1 or 4.2.3 or later to address this vulnerability. The Dell Enterprise SONiC Distribution update is available through the Dell Support website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.