GPU VulnDB

Database/Firmware, BMC & network fabric

Dell SmartFabric OS10: code injection gives a local high-privilege user code execution on the switch

CVSS 6.7CVE-2024-48829Firmware, BMC & network fabriccurated

Impact

SmartFabric OS10 runs Dell's datacenter switches, including the leaf-spine and storage fabric in front of GPU nodes. A high-privileged local user can inject code and execute it on the switch itself, escaping the constrained management CLI into the underlying system. That matters for a fabric that crosses tenants: code on the switch can mirror, redirect or drop traffic and persist below the configuration an operator inspects. The privilege bar is the limiting factor - this is an administrator breaking out of the NOS, not an unauthenticated path in - so it is mostly an insider and post-compromise durability concern rather than a reason for an unplanned window. Note this CVE was published late (2025-11) against a fix in 10.6.1.0.

Who can reach it

Local access to the switch with high privileges already held (administrative CLI or shell on the management plane). No remote unauthenticated path.

What to do

Upgrade SmartFabric OS10 to 10.6.1.0 or later per Dell DSA-2025-407. An OS10 upgrade reloads the switch, so each device needs a maintenance window and the fabric must tolerate losing that leaf or spine - plan it alongside your normal switch-code cycle rather than as an emergency. Meanwhile, limit and audit who holds administrative access to the switches.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.