Database/Firmware, BMC & network fabric
Dell SmartFabric OS10 (command injection): A low-privileged remote attacker executes code on the switch OS
CVSS 8.8CVE-2025-46428Firmware, BMC & network fabriccurated
Impact
A low-privileged remote attacker executes code on the switch OS. On a GPU cluster these switches carry the storage and east-west traffic, so switch compromise means traffic interception across the fabric.
Who can reach it
Authenticated low-privilege access to the switch management plane.
What to do
Upgrade SmartFabric OS10 to 10.6.1.0. Switch OS upgrade with a reboot - do it leaf-by-leaf on a redundant topology, or take a fabric maintenance window.
References
Related entries
- Dell SmartFabric OS10 (command injection): Command injection from a low-privileged local account leading to codeCVE-2024-49557 · Dell SmartFabric OS10 (command injection)High
- Dell SmartFabric OS10 (command injection): A low-privileged local attacker executes commands on the switch OSCVE-2024-49560 · Dell SmartFabric OS10 (command injection)High
- Dell SmartFabric OS10 (command injection): Command injection in SmartFabric OS10 10.5.5.4-10.5.5.10 and 10.5.6.xCVE-2024-38486 · Dell SmartFabric OS10 (command injection)High
- Dell SmartFabric OS10 (command injection): Second command-injection path in the same OS10 advisory, givingCVE-2025-46427 · Dell SmartFabric OS10 (command injection)High
- ATEN eco DC (DCIM/environmental management platform): The web interface doesn't check a user's assigned roleCVE-2025-6685 · ATEN eco DC (DCIM/environmental management platform)High
- Lenovo XClarity Orchestrator (alternate communication channel): An attacker on the LXCO network segment manipulatesCVE-2025-8557 · Lenovo XClarity Orchestrator (alternate communication channel)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.