CVE-2024-45764: Dell Enterprise Sonic Distribution
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. This is a critical severity vulnerability so Dell recommends customers to upgrade at the earliest opportunity.
Affected products
- Dell Enterprise Sonic Distribution: from 4.1.0, before 4.1.6 (fixed in 4.1.6); from 4.2.0, before 4.2.2 (fixed in 4.2.2)
Published 2024-11-08. Last modified 2026-06-17.