Database/Firmware, BMC & network fabric
Dell SmartFabric OS10 (hard-coded password): A hard-coded password in OS10 10.5.6.x gives an unauthenticated attacker
CVSS 8.4CVE-2024-48831Firmware, BMC & network fabriccurated
Impact
A hard-coded password in OS10 10.5.6.x gives an unauthenticated attacker with local access full unauthorized access to the switch. Hard-coded means you cannot rotate it - only the patch removes it.
Who can reach it
Local access to the switch (console, or a compromised management host).
What to do
Upgrade OS10 per DSA-2025-068. Because the credential is hard-coded, there is no config-level mitigation - the firmware upgrade and reboot is the only fix.
References
Related entries
- Dell SmartFabric OS10 (hard-coded password): A hard-coded password in SmartFabric OS10 10.5.5.4-10.5.5.10 and 10.5.6.xCVE-2024-39585 · Dell SmartFabric OS10 (hard-coded password)High
- Supermicro BMC firmware update signature/validation logic on the X13SEM-F motherboard family: The operator losesCVE-2025-12007 · Supermicro BMC firmware update signature/validation logic on the X13SEM-F motherboard familyHigh
- Junos OS: missing authentication in command processing gives a privileged local user root on line cardsCVE-2025-30650 · Juniper Junos OS (command processing on Linux-based line cards: MPC7-11, LC2101/480/9600, MX304, MX-SPC3, PTX FPC3)High
- IBM Power Systems Firmware: HMC-authenticated attacker executes code on the service processorCVE-2026-16832 · IBM Power Systems Firmware (FSP management network protocol)High
- Linux kernel (drivers/infiniband/core): IWARP port-mapper netlink attributes were accepted as plain strings with noCVE-2026-63860 · Linux kernel (drivers/infiniband/core)High
- AMI MegaRAC: Password reset interception via the API — attacker takes over an admin BMC accountCVE-2022-26872 · AMI MegaRACHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.