Database/Firmware, BMC & network fabric
Dell SmartFabric OS10 before 10.6.1.3: code downloaded without integrity check allows code execution
Impact
OS10 downloads code without verifying its integrity, so a high-privileged remote attacker - or anyone who can tamper with the download path the switch trusts - gets code execution on the switch, with a scope change in Dell's 9.1 vector meaning the impact reaches beyond the vulnerable component. Code running on a switch sits below every tenant boundary above it: it can mirror or redirect fabric traffic and it persists across configuration changes. The realistic path for a GPU operator is an image or package pulled during an upgrade or ZTP run; unverified code there means a compromised image server or an on-path attacker turns a routine upgrade into a fabric implant. The record does not name which download path is affected.
Who can reach it
Remote with high privileges on the switch, or an on-path position over the unverified download the switch performs. Effectively the management VLAN plus administrative access or control of the image source.
What to do
Upgrade to OS10 10.6.1.3 or later per Dell advisory DSA-2026-343 - a switch reload, so drain or fail over the rack's uplink first. Meanwhile serve switch images only from a trusted, access-controlled host over an authenticated channel, verify hashes out of band before an upgrade, and keep administrative access to OS10 limited to a jump host.
References
Related entries
- Linux kernel - RDMA/rtrs server (RDMA Transport, used by RNBD block storage), drivers/infiniband/ulp/rtrs/rtrs-srv.cCVE-2026-64269 · Linux kernel - RDMA/rtrs server (RDMA Transport, used by RNBD block storage), drivers/infiniband/ulp/rtrs/rtrs-srv.cCritical
- AMD Secure Processor (Ryzen / Ryzen Pro / Ryzen Mobile): Insufficient access control on the Secure Processor lets codeCVE-2018-8931 · AMD Secure Processor (Ryzen / Ryzen Pro / Ryzen Mobile)Critical
- AMD Secure Processor (Ryzen / Ryzen Pro): The same class of Secure Processor access-control failure as RYZENFALL-1CVE-2018-8932 · AMD Secure Processor (Ryzen / Ryzen Pro)Critical
- Promontory chipset firmware (AMD Ryzen / Ryzen Pro platforms): A backdoor in the Promontory chipset firmware. TheCVE-2018-8934 · Promontory chipset firmware (AMD Ryzen / Ryzen Pro platforms)Critical
- AMD EPYC / Ryzen - Platform Security Processor privilege escalation: A direct privilege escalation into the PlatformCVE-2018-8936 · AMD EPYC / Ryzen - Platform Security Processor privilege escalationCritical
- APC Smart-UPS SmartConnect family (SMT, SMC, SMTL, SCL, SMX series) - cloud-connected UPS firmware: A heap overflow inCVE-2022-22805 · APC Smart-UPS SmartConnect family (SMT, SMC, SMTL, SCL, SMX series) - cloud-connected UPS firmwareCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.