Database/Firmware, BMC & network fabric
Dell SmartFabric OS10: command injection lets a high-privileged remote user run arbitrary OS commands
Impact
An administrator-level account on a Dell SmartFabric OS10 switch can break out of the constrained network CLI and execute arbitrary commands on the underlying switch OS. On a GPU fabric this converts a scoped switch admin credential - the kind handed to network automation, monitoring or a managed-service partner - into full control of a device that carries every tenant's east-west and storage traffic, with the ability to persist below the configuration layer. Because the leaf and spine switches are shared, a single compromised device affects tenants that never touched it. Dell split this across two ids in DSA-2026-322 (CVE-2026-35160 and CVE-2026-63694), same score and same fixed release; the operator action is identical for both.
Who can reach it
Remote over the network, but authentication as a high-privileged (admin-level) OS10 user is required. Realistically this is anyone who can reach the switch management interface and holds admin credentials - so the exposure is governed by management VLAN reach and how widely switch admin accounts are shared.
What to do
Upgrade SmartFabric OS10 to 10.5.6.14 or later per DSA-2026-322. This is a switch image upgrade and reload: plan it per device with the switch out of service, so on a non-redundant fabric leg it means draining or accepting loss of the GPU nodes behind that switch. Until then, restrict management plane reachability and audit who holds admin accounts.
Also covers 1 CVE
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- Eaton UPS 9PX 8000 SP web interface: The device's own web page contains the user password in cleartext in the pageCVE-2018-9279 · Eaton UPS 9PX 8000 SP web interfaceMedium
- NVIDIA DGX BMC (AMI firmware): An administrative BMC user can pull the hash of the BMC/IPMI user passwordCVE-2020-11484 · NVIDIA DGX BMC (AMI firmware)Medium
- AMI MegaRAC SPx 12 / SPx 13 (BMC TLS certificate generation): Malformed input to the BMC's certificate-generationCVE-2021-44769 · AMI MegaRAC SPx 12 / SPx 13 (BMC TLS certificate generation)Medium
- IBM OpenBMC OP910 / OP940 certificate handling (phosphor-certificate-manager lineage): A privileged BMC userCVE-2022-22488 · IBM OpenBMC OP910 / OP940 certificate handling (phosphor-certificate-manager lineage)Medium
- Intel SPS firmware: Uncontrolled resource consumption in SPS firmware lets a privileged user deny serviceCVE-2023-29153 · Intel SPS firmwareMedium
- Dell PowerEdge Server BIOS + iDRAC9 (information disclosure): Information disclosure spanning both the BIOS and iDRAC9CVE-2025-26482 · Dell PowerEdge Server BIOS + iDRAC9 (information disclosure)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.