Database/Firmware, BMC & network fabric
Dell SmartFabric OS10 (command injection): A low-privileged local attacker executes commands on the switch OS
CVSS 7.8CVE-2024-49560Firmware, BMC & network fabriccurated
Impact
A low-privileged local attacker executes commands on the switch OS.
Who can reach it
Local access to the switch CLI with a low-privilege account.
What to do
Upgrade OS10 per DSA-2024-425. Switch reboot required.
References
Related entries
- Dell SmartFabric OS10 (command injection): Command injection in SmartFabric OS10 10.5.5.4-10.5.5.10 and 10.5.6.xCVE-2024-38486 · Dell SmartFabric OS10 (command injection)High
- Dell SmartFabric OS10 (command injection): Second command-injection path in the same OS10 advisory, givingCVE-2025-46427 · Dell SmartFabric OS10 (command injection)High
- Dell SmartFabric OS10 (command injection): A low-privileged remote attacker executes code on the switch OSCVE-2025-46428 · Dell SmartFabric OS10 (command injection)High
- Dell SmartFabric OS10 (command injection): Command injection from a low-privileged local account leading to codeCVE-2024-49557 · Dell SmartFabric OS10 (command injection)High
- Dell SmartFabric OS10 (incorrect privilege assignment): Local low-privilege attacker escalates privileges on the switchCVE-2024-49561 · Dell SmartFabric OS10 (incorrect privilege assignment)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): When a DMA mapping fails on the multi-packet transmit path, theCVE-2024-50001 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.