CVE-2023-28078
Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A remote unauthenticated attacker could potentially exploit this vulnerability leading to information disclosure and a possible Denial of Service when a huge number of requests are sent to the switch. This is a high severity vulnerability as it allows an attacker to view sensitive data. Dell recommends customers to upgrade at the earliest opportunity.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- EPSS probability
- 0.37%
- CWE
- CWE-923
- Published
- 2024-02-15
- Last modified
- 2026-03-13
Affected products
- Dell Dell SmartFabric OS10
- Dell Dell SmartFabric OS10
- Dell Dell SmartFabric OS10
- Dell Dell SmartFabric OS10
- Dell Dell SmartFabric OS10
- Dell Dell SmartFabric OS10
- Dell Dell SmartFabric OS10
- Dell Dell SmartFabric OS10
Weakness type
Related vulnerabilities
- CVE-2019-17440 — PAN-OS on PA-7000 Series: Improper restriction of communication to Log Forwarding Card (LFC) allows root access
- CVE-2026-34205 — Home Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network Mode
- CVE-2017-3891 — In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default conf
- CVE-2025-61939 — Columbia Weather Systems MicroServer Improper Restriction of Communication Channel to Intended Endpoints
- CVE-2025-20261 — Cisco Integrated Management Controller Privilege Escalation Vulnerability
- CVE-2021-38487 — Potential Network Amplification and Information Exposure in RTI Connext Professional and Connext Micro
- CVE-2025-58742 — Insufficient Configuration Protections Enable Database Credential Interception in Milner ImageDirector Capture
- CVE-2024-26131 — Element Android Intent Redirection