SB2025033110 - Dell Connectrix MDS series update for Cisco bootloader vulnerability
Published: March 31, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Verification of Cryptographic Signature (CVE-ID: CVE-2024-20397)
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to improper signature verification in the bootloader. An attacker with physical access to device or a user with administrative privileges can bypass NX-OS image signature verification and load unverified software.
Remediation
Install update from vendor's website.
References
- https://www.dell.com/support/kbdoc/nl-nl/000261082/dsa-2025-023-security-update-for-dell-connectrix-mds-cisco-bootloader-vulnerability"
- https://www.dell.com/support/kbdoc/nl-nl/000261082/dsa-2025-023-security-update-for-dell-connectrix-mds-cisco-bootloader-vulnerability</a></p><p>
- https://www.dell.com/support/home/nl-nl/product-support/product/connectrix-mds-series-hardware/drivers</p><p><br></p>