Executive brief
Dell SmartFabric OS10 is networking switch software that provides fabric management and operational control. This command injection vulnerability allows an authenticated attacker with high privileges to execute arbitrary commands on the affected switch, potentially compromising network infrastructure and enabling lateral movement through the fabric.
Technical details
The vulnerability is an improper neutralization of special elements in a command injection attack (CWE-78). A high-privileged attacker with remote network access can exploit this by crafting malicious input that bypasses input validation, resulting in arbitrary OS command execution on the switch. The vulnerability requires high privileges and network connectivity, but no user interaction. The fix is available in Dell SmartFabric OS10 version 10.5.6.14 and later.
Affected products
- Dell SmartFabric OS10 prior to 10.5.6.14
Timeline
- 2026-09-03: disclosed