Database/Firmware, BMC & network fabric
Dell SmartFabric OS10 (incorrect privilege assignment): Local low-privilege attacker escalates privileges on the switch
CVSS 7.8CVE-2024-49561Firmware, BMC & network fabriccurated
Impact
Local low-privilege attacker escalates privileges on the switch OS.
Who can reach it
Local low-privilege switch access.
What to do
Upgrade OS10 per DSA-2025-070/069/079.
References
Related entries
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): When a DMA mapping fails on the multi-packet transmit path, theCVE-2024-50001 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)High
- Linux kernel (drivers/infiniband/hw/bnxt_re): Collecting hardware counters writes doorbell-pacing statistics into aCVE-2024-50158 · Linux kernel (drivers/infiniband/hw/bnxt_re)High
- Linux kernel (drivers/infiniband/hw/bnxt_re): Building the two-level page list for a large RDMA resource assumesCVE-2024-50208 · Linux kernel (drivers/infiniband/hw/bnxt_re)High
- Linux kernel mlx5_core eswitch vport representors / IPsec FS: During driver unload the vport representor private structCVE-2024-57801 · Linux kernel mlx5_core eswitch vport representors / IPsec FSHigh
- Linux kernel RDMA core (ib_uverbs post_send / post_recv command parsing): The uverbs write path multiplied two fullyCVE-2024-57890 · Linux kernel RDMA core (ib_uverbs post_send / post_recv command parsing)High
- GRUB2 (squashfs): Integer overflow in the squash4 filesystem module leading to out-of-bounds write and possible SecureCVE-2025-0678 · GRUB2 (squashfs)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.