« Volver al listado

CVE-2023-28078

Estado: AnalizadaCrítica (9.1)—

Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A remote unauthenticated attacker could potentially exploit this vulnerability leading to information disclosure and a possible Denial of Service when a huge number of requests are sent to the switch. This is a high severity vulnerability as it allows an attacker to view sensitive data. Dell recommends customers to upgrade at the earliest opportunity.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-28078",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-28078",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-02-15T19:48:03.918241Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security_alert@emc.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "Dell",
          "product": "Dell SmartFabric OS10",
          "versions": [
            {
              "status": "affected",
              "version": "10.5.5.0"
            },
            {
              "status": "affected",
              "version": "10.5.5.3"
            },
            {
              "status": "affected",
              "version": "10.5.5.1 (MX)"
            },
            {
              "status": "affected",
              "version": "10.5.5.2 (MX)"
            },
            {
              "status": "affected",
              "version": "10.5.4.x"
            },
            {
              "status": "affected",
              "version": "10.5.4.6 (MX)"
            },
            {
              "status": "affected",
              "version": "10.5.3.x"
            },
            {
              "status": "affected",
              "version": "10.5.2.x"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:dell:smartfabric_os10:*:*:*:*:*:*:*:*"
          ],
          "vendor": "dell",
          "product": "smartfabric_os10",
          "versions": [
            {
              "status": "affected",
              "version": "10.5.5.0"
            },
            {
              "status": "affected",
              "version": "10.5.5.3"
            },
            {
              "status": "affected",
              "version": "10.5.5.1\\(mx\\)"
            },
            {
              "status": "affected",
              "version": "10.5.5.2\\(mx\\)"
            },
            {
              "status": "affected",
              "version": "10.5.2.0",
              "lessThan": "10.5.5.0",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "10.5.4.6\\(mx\\)"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-02-15T13:15:44.607",
  "references": [
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000216584/dsa-2023-124-security-update-for-dell-smartfabric-os10-multiple-vulnerabilities",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000216584/dsa-2023-124-security-update-for-dell-smartfabric-os10-multiple-vulnerabilities",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security_alert@emc.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-923"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\nDell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A remote unauthenticated attacker could potentially exploit this vulnerability leading to information disclosure and a possible Denial of Service when a huge number of requests are sent to the switch. This is a high severity vulnerability as it allows an attacker to view sensitive data. Dell recommends customers to upgrade at the earliest opportunity.\n\n"
    },
    {
      "lang": "es",
      "value": "Los conmutadores de red Dell OS10 que ejecutan 10.5.2.x y versiones posteriores contienen una vulnerabilidad con zeroMQ cuando se configura VLT. Un atacante remoto no autenticado podría explotar esta vulnerabilidad, lo que provocaría la divulgación de información y una posible denegación de servicio cuando se envía una gran cantidad de solicitudes al conmutador. Esta es una vulnerabilidad de alta gravedad ya que permite a un atacante ver datos confidenciales. Dell recomienda a los clientes actualizar lo antes posible."
    }
  ],
  "lastModified": "2026-06-17T05:46:48.847",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dell:smartfabric_os10:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1740757D-7955-4DAF-9823-78D2E8121FD6",
              "versionEndExcluding": "10.5.2.12",
              "versionStartIncluding": "10.5.2.0"
            },
            {
              "criteria": "cpe:2.3:o:dell:smartfabric_os10:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A714316-8AC3-4150-B31F-4AC3132B4A45",
              "versionEndExcluding": "10.5.3.8",
              "versionStartIncluding": "10.5.3.0"
            },
            {
              "criteria": "cpe:2.3:o:dell:smartfabric_os10:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DDA673E9-390C-45C8-94A8-D2B82B22E699",
              "versionEndExcluding": "10.5.4.8",
              "versionStartIncluding": "10.5.4.0"
            },
            {
              "criteria": "cpe:2.3:o:dell:smartfabric_os10:10.5.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DF0C9317-1643-40E0-B5E2-D8EA13709FB3"
            },
            {
              "criteria": "cpe:2.3:o:dell:smartfabric_os10:10.5.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C1EB5550-61C9-438E-8387-2787907807B7"
            },
            {
              "criteria": "cpe:2.3:o:dell:smartfabric_os10:10.5.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5800770C-78AD-4754-ACD4-3E9A4FAD28ED"
            },
            {
              "criteria": "cpe:2.3:o:dell:smartfabric_os10:10.5.5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ADE2AF35-19FA-4759-B1FE-604A681A5329"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}