Database/Firmware, BMC & network fabric
Dell SmartFabric OS10 (command injection): Command injection in SmartFabric OS10 10.5.5.4-10.5.5.10 and 10.5.6.x
Impact
Command injection in SmartFabric OS10 10.5.5.4-10.5.5.10 and 10.5.6.x. Listed as a distinct entry because its affected-version window is narrower than the later OS10 command-injection batch, so a fleet on 10.5.5.x needs this specific fix even if it has applied a 10.6.x-targeted advisory elsewhere.
Who can reach it
An attacker able to supply input to the affected OS10 command path.
What to do
OS10 upgrade plus switch reload. Verify the fixed-version table against your exact running build — Dell's OS10 advisories have heavily overlapping but non-identical version ranges and it is easy to conclude you are patched when you are not.
References
Related entries
- Dell SmartFabric OS10 (command injection): Second command-injection path in the same OS10 advisory, givingCVE-2025-46427 · Dell SmartFabric OS10 (command injection)High
- Dell SmartFabric OS10 (command injection): A low-privileged remote attacker executes code on the switch OSCVE-2025-46428 · Dell SmartFabric OS10 (command injection)High
- Dell SmartFabric OS10 (command injection): Command injection from a low-privileged local account leading to codeCVE-2024-49557 · Dell SmartFabric OS10 (command injection)High
- Dell SmartFabric OS10 (command injection): A low-privileged local attacker executes commands on the switch OSCVE-2024-49560 · Dell SmartFabric OS10 (command injection)High
- Linux kernel - RDMA/rxe unreliable datagram responder, drivers/infiniband/sw/rxe/rxe_resp.c: The IB architecture says aCVE-2024-40992 · Linux kernel - RDMA/rxe unreliable datagram responder, drivers/infiniband/sw/rxe/rxe_resp.cHigh
- Linux kernel NVMe-oF RDMA target (nvmet, uninitialised completion-entry result field): This is a straight kernel-stackCVE-2024-41079 · Linux kernel NVMe-oF RDMA target (nvmet, uninitialised completion-entry result field)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.