CVE-2024-45764
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. This is a critical severity vulnerability so Dell recommends customers to upgrade at the earliest opportunity.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.52%
- CWE
- CWE-304
- Published
- 2024-11-08
- Last modified
- 2026-03-13
Affected products
- Dell Enterprise SONiC OS
Weakness type
Related vulnerabilities
- CVE-2022-2302 — LENZE: Missing password verification in authorisation procedure
- CVE-2024-8954 — Authentication Bypass in composiohq/composio
- CVE-2022-2821 — Missing Critical Step in Authentication in namelessmc/nameless
- CVE-2024-12048 — IDOR Vulnerability in transformeroptimus/superagi
- CVE-2019-16766 — 2FA bypass in Wagtail through new device path
- CVE-2026-55957 — Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
- CVE-2024-2172 — Malware Scanner <= 4.7.2 and Web Application Firewall <= 2.1.1 - Unauthenticated Privilege Escalation
- CVE-2022-1065 — Multi Factor Authentication Bypass in various versions of Abacus ERP