Impact
The vulnerability is an OS command injection flaw that allows a high privileged attacker with remote access to execute arbitrary system commands on the device. It arises from improper neutralization of special elements used in an OS command. The impact is the potential for an attacker to gain full control over the affected system, leading to data compromise, service disruption, or further lateral movement. The weakness is identified as CWE-78.
Affected Systems
Dell SmartFabric OS10 Software versions before 10.5.6.14 are affected. These include all network switches running that OS version where a user with high level privileges can reach the device remotely. The vulnerability does not affect community or embedded editions explicitly listed by Dell, and no other vendors or product variants are known to be impacted.
Risk and Exploitability
The CVSS base score is 5, indicating moderate severity. The EPSS score is 1%, indicating a very low but nonzero exploitation probability; however, the requirement for high-privileged remote access limits potential attackers. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported yet. An attacker with the necessary credentials could trigger the flaw by sending crafted input to the OS command interface, resulting in command execution.
OpenCVE Enrichment