Database/Firmware, BMC & network fabric
Dell SmartFabric OS10 (XML external entity): XXE in SmartFabric OS10 before 10.6.0.5, reachable remotely
CVE-2025-36608Firmware, BMC & network fabriccurated
Impact
XXE in SmartFabric OS10 before 10.6.0.5, reachable remotely by a low-privileged attacker. XXE on a switch typically yields file read from the switch's filesystem — which holds the running configuration, and therefore the fabric's secrets and its full topology.
Who can reach it
Low-privileged attacker with remote access to the OS10 management interface.
What to do
Upgrade OS10 to 10.6.0.5 or later plus reload. Related file-exposure issue in the same release: CVE-2025-30103.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.