Database/Firmware, BMC & network fabric
Dell SmartFabric OS10 (command injection): A low-privileged remote attacker executes code on the switch OS
CVE-2025-46428Firmware, BMC & network fabriccurated
Impact
A low-privileged remote attacker executes code on the switch OS. On a GPU cluster these switches carry the storage and east-west traffic, so switch compromise means traffic interception across the fabric.
Who can reach it
Authenticated low-privilege access to the switch management plane.
What to do
Upgrade SmartFabric OS10 to 10.6.1.0. Switch OS upgrade with a reboot - do it leaf-by-leaf on a redundant topology, or take a fabric maintenance window.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.