Database/Firmware, BMC & network fabric
Dell SmartFabric OS10 (execution with unnecessary privileges): A low-privileged attacker escalates through an OS10
Impact
A low-privileged attacker escalates through an OS10 component running with more privilege than it needs. OS10 is a Linux-based NOS, so escalation here is root on a box that programs the forwarding ASIC — arbitrary control over which tenant's traffic goes where. Sits alongside a long series of OS10 command-injection findings (CVE-2024-48830, CVE-2024-49557, CVE-2024-49560, CVE-2025-22472, CVE-2025-22473, CVE-2025-46427, CVE-2025-46428) that all give a low-privileged local or remote user a path to root.
Who can reach it
Low-privileged attacker with access to the switch, versions 10.5.4.x through 10.6.0.x.
What to do
OS10 upgrade plus reload. Because so many of these share the same precondition — a low-privileged account on the switch — the highest-leverage control is eliminating low-privilege switch accounts entirely and driving all changes through an automation account on a bastion.
References
Related entries
- Dell SmartFabric OS10 (execution with unnecessary privileges): Low-privileged local attacker reaches command executionCVE-2024-48837 · Dell SmartFabric OS10 (execution with unnecessary privileges)High
- Dell SmartFabric OS10 (default password): A default password in SmartFabric OS10 across 10.5.4.x through 10.6.0.xCVE-2024-49559 · Dell SmartFabric OS10 (default password)High
- Linux kernel mlx5_ib (InfiniBand/RoCE completion queue polling): mlx5_poll_one() compares the firmware's QP numberCVE-2025-22086 · Linux kernel mlx5_ib (InfiniBand/RoCE completion queue polling)High
- Dell SmartFabric OS10 (command injection): Second command-injection path in the same OS10 advisory, givingCVE-2025-46427 · Dell SmartFabric OS10 (command injection)High
- Dell SmartFabric OS10 (command injection): A low-privileged remote attacker executes code on the switch OSCVE-2025-46428 · Dell SmartFabric OS10 (command injection)High
- ATEN eco DC (DCIM/environmental management platform): The web interface doesn't check a user's assigned roleCVE-2025-6685 · ATEN eco DC (DCIM/environmental management platform)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.