Database/Firmware, BMC & network fabric
Dell SmartFabric OS10 (default password): A default password in SmartFabric OS10 across 10.5.4.x through 10.6.0.x
Impact
A default password in SmartFabric OS10 across 10.5.4.x through 10.6.0.x, usable remotely by a low-privileged attacker to escalate. Default credentials on a datacenter switch are the same failure the BMC world has been fighting for a decade — the switch arrives with a working account nobody in the deployment checklist knows to remove.
Who can reach it
Low-privileged attacker with remote access to the switch.
What to do
OS10 upgrade plus reload. Also add a switch-intake step that enumerates and disables every non-provisioned local account, the same way you rotate BMC credentials at rack intake — a process change that catches the next one of these before an advisory does.
References
Related entries
- Linux kernel mlx5_ib (InfiniBand/RoCE completion queue polling): mlx5_poll_one() compares the firmware's QP numberCVE-2025-22086 · Linux kernel mlx5_ib (InfiniBand/RoCE completion queue polling)High
- Dell SmartFabric OS10 (command injection): Second command-injection path in the same OS10 advisory, givingCVE-2025-46427 · Dell SmartFabric OS10 (command injection)High
- Dell SmartFabric OS10 (command injection): A low-privileged remote attacker executes code on the switch OSCVE-2025-46428 · Dell SmartFabric OS10 (command injection)High
- ATEN eco DC (DCIM/environmental management platform): The web interface doesn't check a user's assigned roleCVE-2025-6685 · ATEN eco DC (DCIM/environmental management platform)High
- Lenovo XClarity Orchestrator (alternate communication channel): An attacker on the LXCO network segment manipulatesCVE-2025-8557 · Lenovo XClarity Orchestrator (alternate communication channel)High
- Lenovo XClarity Integrator for Windows Admin Center (PowerShell command injection): PowerShell command injectionCVE-2026-14371 · Lenovo XClarity Integrator for Windows Admin Center (PowerShell command injection)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.