Impact
Dell SmartFabric OS10 Software contains a command injection vulnerability caused by improper neutralization of special elements used in a command. This flaw allows a high privileged attacker who can reach the device remotely to inject arbitrary commands, resulting in execution of those commands on the system. The potential impact includes full compromise of the device’s confidentiality, integrity, and availability, giving the attacker control over network infrastructure components.
Affected Systems
The affected vendor is Dell, and the product is SmartFabric OS10. Versions before 10.5.6.12 are vulnerable; all later releases include the remediation.
Risk and Exploitability
The assigned CVSS score of 6.6 reflects moderate to high severity. With an EPSS score of less than 1% and no listing in the CISA KEV catalog, the likelihood of exploitation in the wild is low but not zero. The attack requires remote access and high-level administrative privileges, indicating that the vulnerability is reachable over network management channels and can be leveraged by attackers who have compromised privileged credentials or adjacent network components.
OpenCVE Enrichment