CVE-2025-46427
8.8Dell · SmartFabric OS10 Software
Dell SmartFabric OS10 software prior to version 10.6.1.0 is vulnerable to command injection, allowing low privileged remote attackers to execute arbitrary commands.
Executive summary
A critical command injection vulnerability in Dell SmartFabric OS10 allows low privileged remote attackers to achieve full system compromise.
Vulnerability
This is a command injection flaw (CWE-77) occurring due to improper neutralization of special elements in command strings. An attacker with low privileges and remote network access can exploit this vulnerability to execute arbitrary commands on the underlying operating system.
Business impact
The ability to execute arbitrary commands on network infrastructure components poses a severe risk to organizational security. Successful exploitation could lead to total system takeover, unauthorized access to sensitive network traffic, and potential lateral movement within the environment. With a CVSS score of 8.8, this vulnerability represents a high risk to availability, integrity, and confidentiality of the affected network fabric.
Remediation
Immediate Action: Upgrade all instances of Dell SmartFabric OS10 software to version 10.6.1.0 or later as specified in the official vendor security advisory.
Proactive Monitoring: Inspect system logs for unusual command execution patterns or unauthorized access attempts originating from lower privileged service accounts.
Compensating Controls: Implement strict network segmentation and restrict management interface access to trusted administrative subnets to minimize the exposure of vulnerable services.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS severity and the potential for complete system compromise, administrators should prioritize this update within their standard patching cycle. Verify the current version of all SmartFabric OS10 deployments and move to patch version 10.6.1.0 immediately to eliminate the command injection vector.
More Dell CVEs
Sources
Originally found and disclosed by Dell would like to thank kkking for reporting these issues., per the CVE Program record.