Loading HuntDB...

GHSA-6x85-j5hx-4hj5

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. This is a critical severity vulnerability as it allows high privilege OS commands to be executed with a less privileged role; so Dell recommends customers to upgrade at the earliest opportunity.

Related CVEs

Key Information

GHSA ID
GHSA-6x85-j5hx-4hj5
Published
November 8, 2024 6:30 PM
Last Modified
November 8, 2024 6:30 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 10, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.