Database/Firmware, BMC & network fabric
Dell SmartFabric OS10 (command injection with elevated privileges): Local low-privilege attacker executes commands
CVSS 7.8CVE-2025-22472Firmware, BMC & network fabriccurated
Impact
Local low-privilege attacker executes commands at elevated privilege on the switch.
Who can reach it
Local low-privilege access to OS10.
What to do
Upgrade OS10 per DSA-2025-070/069/079.
References
Related entries
- Dell SmartFabric OS10 (command injection, local): A low-privileged local attacker achieves code execution on the switchCVE-2025-22473 · Dell SmartFabric OS10 (command injection, local)High
- AMI AptioV BIOS (out-of-bounds write): Second local out-of-bounds write in the same AptioV advisoryCVE-2025-22831 · AMI AptioV BIOS (out-of-bounds write)High
- AMI AptioV BIOS (out-of-bounds write): Local out-of-bounds write in firmware causing data corruption and lossCVE-2025-22832 · AMI AptioV BIOS (out-of-bounds write)High
- Dell iDRAC Tools (improper access control): A low-privileged local attacker escalates privileges through the iDRACCVE-2025-27689 · Dell iDRAC Tools (improper access control)High
- AMI AptioV BIOS (out-of-bounds memory operation): Local attacker causes firmware memory corruption impacting integrityCVE-2025-33044 · AMI AptioV BIOS (out-of-bounds memory operation)High
- Linux bnxt_en driver (ethtool coredump / bnxt_get_coredump): Out-of-bounds memcpy when retrieving a firmware coredumpCVE-2025-37911 · Linux bnxt_en driver (ethtool coredump / bnxt_get_coredump)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.