CVE-2023-39248

HIGH

Dell Networking OS10 10.5.2.x and above - Unauthenticated Denial of Service via VLT and VRRP Configuration

Title source: llm
STIX 2.1

Description

Dell OS10 Networking Switches running 10.5.2.x and above contain an Uncontrolled Resource Consumption (Denial of Service) vulnerability, when switches are configured with VLT and VRRP. A remote unauthenticated user can cause the network to be flooded leading to Denial of Service for actual network users. This is a high severity vulnerability as it allows an attacker to cause an outage of network. Dell recommends customers to upgrade at the earliest opportunity.

Scores

CVSS v3 7.5
EPSS 0.0014
EPSS Percentile 32.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (1)
dell/networking_os10 10.5.5.5
Published Dec 05, 2023
Tracked Since Feb 18, 2026