PT-2022-5021 · Dell · Dell Enterprise Sonic Os

CVE-2022-34425

·

Published

2022-10-10

·

Updated

2022-10-13

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dell Enterprise SONiC OS versions 4.0.0 through 4.0.1
Description The issue is related to a cryptographic key vulnerability in SSH, where an unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to communication. This vulnerability is associated with the use of a hardcoded cryptographic key, which could allow a remote attacker to disclose protected information.
Recommendations For versions 4.0.0 and 4.0.1, consider disabling SSH access until a patch is available to prevent potential exploitation. As a temporary workaround, restrict access to SSH to minimize the risk of unauthorized access to communication.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06234
CVE-2022-34425

Affected Products

Dell Enterprise Sonic Os