CVE-2025-46428

8.8

Dell · SmartFabric OS10 Software

Dell SmartFabric OS10 Software contains a command injection vulnerability that allows low privileged remote attackers to achieve code execution.

Executive summary

A command injection vulnerability in Dell SmartFabric OS10 Software, fixed in version 10.6.1.0, poses a severe risk of unauthorized remote code execution.

Vulnerability

This is a command injection vulnerability (CWE-77) occurring due to improper neutralization of special elements in commands. The vulnerability can be triggered by a low privileged attacker with remote access to the system.

Business impact

The ability for a remote attacker to execute arbitrary code on networking infrastructure presents a significant threat to organizational security. Successful exploitation could lead to full system compromise, unauthorized data access, and disruption of critical network services, which justifies the high CVSS score of 8.8.

Remediation

Immediate Action: Upgrade all instances of Dell SmartFabric OS10 Software to version 10.6.1.0 or later to patch the underlying command injection flaw.

Proactive Monitoring: Review device access logs for unusual command execution patterns or unauthorized attempts to access management interfaces.

Compensating Controls: Restrict management interface access to trusted administrative IP addresses and employ network segmentation to limit exposure to potentially untrusted network segments.

Exploitation status

Public Exploit Available: exploit_available (false)

Analyst recommendation

Given the potential for remote code execution and the critical role of network operating systems, this vulnerability should be prioritized for remediation. Administrators must verify their current version of SmartFabric OS10 and apply the 10.6.1.0 update immediately to prevent potential exploitation.

More Dell CVEs

Sources

Originally found and disclosed by Dell would like to thank kkking for reporting these issues., per the CVE Program record.