Database/Firmware, BMC & network fabric
Dell SmartFabric OS10 (XML external entity): XXE in SmartFabric OS10 before 10.6.0.5, reachable remotely
CVSS 6.5CVE-2025-36608Firmware, BMC & network fabriccurated
Impact
XXE in SmartFabric OS10 before 10.6.0.5, reachable remotely by a low-privileged attacker. XXE on a switch typically yields file read from the switch's filesystem — which holds the running configuration, and therefore the fabric's secrets and its full topology.
Who can reach it
Low-privileged attacker with remote access to the OS10 management interface.
What to do
Upgrade OS10 to 10.6.0.5 or later plus reload. Related file-exposure issue in the same release: CVE-2025-30103.
References
Related entries
- Linux kernel (drivers/infiniband/core): Bursts of network neighbour updates crash the node. Each event re-initializes aCVE-2025-37772 · Linux kernel (drivers/infiniband/core)Medium
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en_accel): All IPsec offload objects on a physical function shareCVE-2026-23441 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en_accel)Medium
- Linux kernel RDS over InfiniBand (FRMR registration before connection establishment): An RDS sendmsg carryingCVE-2026-31425 · Linux kernel RDS over InfiniBand (FRMR registration before connection establishment)Medium
- HPE iLO 6 (denial of service): An unauthenticated attacker on an adjacent network can knock out iLO 6 availabilityCVE-2026-63457 · HPE iLO 6 (denial of service)Medium
- Dell OpenManage Enterprise: XML external entity processing exposes information to a low-privileged userCVE-2026-70423 · Dell OpenManage Enterprise (XML external entity processing)Medium
- Dell OpenManage Enterprise: path traversal exposes information to a low-privileged remote userCVE-2026-70424 · Dell OpenManage Enterprise (path traversal in a restricted-directory check)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.