Executive brief
Dell SmartFabric OS10 is network operating system software used in datacenter switches and infrastructure. This vulnerability allows a high-privileged attacker with remote access to download and execute arbitrary code on the device without verification, potentially compromising network infrastructure, disrupting operations, and enabling lateral movement across the datacenter.
Technical details
This vulnerability is a CWE-494 "Download of Code Without Integrity Check" flaw in Dell SmartFabric OS10 versions prior to 10.6.1.3. The vulnerable component fails to validate the integrity or authenticity of downloaded code before execution. An attacker with high-level privileges and remote network access can exploit this to download and execute malicious code, achieving arbitrary code execution on the affected device. Dell has released patched version 10.6.1.3 and later as remediation.
Affected products
- Dell SmartFabric OS10 prior to 10.6.1.3
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Version 10.6.1.3 and later