CVE-2024-45765
CVSS 3.1 Score 7.2 of 10 (high)
Details
Published Nov 8, 2024
Updated: Nov 13, 2024
CWE ID 78
Summary
CVE-2024-45765 is a critical OS Command Injection vulnerability affecting Dell Enterprise SONiC OS versions 4.1.x and 4.2.x. An attacker with remote access and high privileges can take advantage of this vulnerability, potentially executing high privilege OS commands using a less privileged role. The risk is significant as it could lead to unauthorized command execution, and Dell strongly advises customers to upgrade their OS as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.