GPU VulnDB

Database/Firmware, BMC & network fabric

Dell SmartFabric Storage Software: Improper input validation in Dell SmartFabric Storage Software 1.3 and lower

CVE-2023-32485Firmware, BMC & network fabriccurated

Impact

Improper input validation in Dell SmartFabric Storage Software 1.3 and lower, exploitable by a remote unauthenticated attacker. SmartFabric Storage Software is the NVMe-over-TCP fabric controller — it performs the discovery and zoning that decides which host initiators can see which NVMe subsystems. Compromising it is compromising the storage access-control layer for the whole cluster. Companion unauthenticated command injection: CVE-2022-31232.

Who can reach it

Unauthenticated, remote to the SmartFabric Storage Software service.

What to do

Upgrade the SmartFabric Storage Software appliance/VM past 1.3 (and past 1.4 for the CVE-2023-4306x set). Application upgrade with a service restart; NVMe-oF sessions reconnect. Afterwards, re-verify the zoning database against intent, because an attacker with control here would change exactly that.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.