CVE-2025-23374: Dell Enterprise Sonic Distribution
Medium severity, CVSS 4.9. EPSS: 0.3% chance of exploitation in the next 30 days.
Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Affected products
- Dell Enterprise Sonic Distribution: before 4.2.3 (fixed in 4.2.3); version 4.4.0 only
Published 2025-01-30. Last modified 2026-06-17.