Database/Firmware, BMC & network fabric
Dell SmartFabric OS10: code injection gives a local high-privilege user code execution on the switch
Impact
SmartFabric OS10 runs Dell's datacenter switches, including the leaf-spine and storage fabric in front of GPU nodes. A high-privileged local user can inject code and execute it on the switch itself, escaping the constrained management CLI into the underlying system. That matters for a fabric that crosses tenants: code on the switch can mirror, redirect or drop traffic and persist below the configuration an operator inspects. The privilege bar is the limiting factor - this is an administrator breaking out of the NOS, not an unauthenticated path in - so it is mostly an insider and post-compromise durability concern rather than a reason for an unplanned window. Note this CVE was published late (2025-11) against a fix in 10.6.1.0.
Who can reach it
Local access to the switch with high privileges already held (administrative CLI or shell on the management plane). No remote unauthenticated path.
What to do
Upgrade SmartFabric OS10 to 10.6.1.0 or later per Dell DSA-2025-407. An OS10 upgrade reloads the switch, so each device needs a maintenance window and the fabric must tolerate losing that leaf or spine - plan it alongside your normal switch-code cycle rather than as an emergency. Meanwhile, limit and audit who holds administrative access to the switches.
References
Related entries
- Dell iDRAC9 / iDRAC10 (path traversal): A high-privileged remote attacker traverses paths on the BMC filesystemCVE-2025-22397 · Dell iDRAC9 / iDRAC10 (path traversal)Medium
- IBM Power Systems host firmware: crafted service-processor command leaks protected registersCVE-2026-19321 · IBM Power Systems host firmware (service processor register access path)Medium
- Junos mgd: null pointer dereference on an SSH configuration change crashes the management daemonCVE-2026-21901 · Juniper Junos OS / Junos OS Evolved management daemon (mgd)Medium
- HPE iLO 5 (firmware update security restriction bypass): Bypass of the security restrictions that guard iLO 5 firmwareCVE-2018-7113 · HPE iLO 5 (firmware update security restriction bypass)Medium
- AMI MegaRAC SPx (BMC hard-coded credentials): Hard-coded credentials inside the BMC firmwareCVE-2023-34473 · AMI MegaRAC SPx (BMC hard-coded credentials)Medium
- Cisco FXOS / NX-OS (LLDP frame handling denial of service): An unauthenticated adjacent attacker sends crafted LLDPCVE-2024-20294 · Cisco FXOS / NX-OS (LLDP frame handling denial of service)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.