Missing Critical Step in Authentication
CVE-2024-45764
Summary
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. This is a critical severity vulnerability so Dell recommends customers to upgrade at the earliest opportunity.
- HIGH
- NETWORK
- HIGH
- CHANGED
- NONE
- NONE
- HIGH
- HIGH
CWE-304 - Missing Critical Step in Authentication
The software implements an authentication technique, but it skips a step that weakens the technique.
References
Advisory Timeline
- Published