Database/Firmware, BMC & network fabric
Dell SmartFabric OS10 (command injection, local): A low-privileged local attacker achieves code execution on the switch
CVSS 7.8CVE-2025-22473Firmware, BMC & network fabriccurated
Impact
A low-privileged local attacker achieves code execution on the switch operating system.
Who can reach it
Local low-privilege access to OS10 10.5.4.x-10.6.0.x.
What to do
Upgrade OS10 per DSA-2025-070/069/079. Switch reboot.
References
Related entries
- AMI AptioV BIOS (out-of-bounds write): Second local out-of-bounds write in the same AptioV advisoryCVE-2025-22831 · AMI AptioV BIOS (out-of-bounds write)High
- AMI AptioV BIOS (out-of-bounds write): Local out-of-bounds write in firmware causing data corruption and lossCVE-2025-22832 · AMI AptioV BIOS (out-of-bounds write)High
- Dell iDRAC Tools (improper access control): A low-privileged local attacker escalates privileges through the iDRACCVE-2025-27689 · Dell iDRAC Tools (improper access control)High
- AMI AptioV BIOS (out-of-bounds memory operation): Local attacker causes firmware memory corruption impacting integrityCVE-2025-33044 · AMI AptioV BIOS (out-of-bounds memory operation)High
- Linux bnxt_en driver (ethtool coredump / bnxt_get_coredump): Out-of-bounds memcpy when retrieving a firmware coredumpCVE-2025-37911 · Linux bnxt_en driver (ethtool coredump / bnxt_get_coredump)High
- Linux kernel Soft-RoCE completion queue (rdma_rxe, rxe_cq_cleanup on create failure): Syzkaller-found slabCVE-2025-38024 · Linux kernel Soft-RoCE completion queue (rdma_rxe, rxe_cq_cleanup on create failure)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.