Description
Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Published: 2026-09-03
Score: 5 Medium
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an OS command injection flaw that allows a high privileged attacker with remote access to execute arbitrary system commands on the device. It arises from improper neutralization of special elements used in an OS command. The impact is the potential for an attacker to gain full control over the affected system, leading to data compromise, service disruption, or further lateral movement. The weakness is identified as CWE-78.

Affected Systems

Dell SmartFabric OS10 Software versions before 10.5.6.14 are affected. These include all network switches running that OS version where a user with high level privileges can reach the device remotely. The vulnerability does not affect community or embedded editions explicitly listed by Dell, and no other vendors or product variants are known to be impacted.

Risk and Exploitability

The CVSS base score is 5, indicating moderate severity. The EPSS score is 1%, indicating a very low but nonzero exploitation probability; however, the requirement for high-privileged remote access limits potential attackers. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported yet. An attacker with the necessary credentials could trigger the flaw by sending crafted input to the OS command interface, resulting in command execution.

Generated by OpenCVE AI on September 4, 2026 at 15:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell update that releases SmartFabric OS10 version 10.5.6.14 or later to fix the command injection flaw
  • Revoke or limit high‑privileged remote access to the switches, enforcing least privilege and using secure management channels
  • Configure network segmentation and firewall rules to block unauthorized network access to the control interfaces of SmartFabric devices

Generated by OpenCVE AI on September 4, 2026 at 15:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell SmartFabric OS10 Software

Thu, 03 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell SmartFabric OS10 Software

Thu, 03 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell smartfabric Os10 Software
Vendors & Products Dell
Dell smartfabric Os10 Software

Thu, 03 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Dell Smartfabric Os10 Software
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-04T03:56:00.797Z

Reserved: 2026-04-01T17:04:27.475Z

Link: CVE-2026-35160

cve-icon Vulnrichment

Updated: 2026-09-03T15:04:18.414Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-03T15:17:25.127

Modified: 2026-09-04T04:17:57.733

Link: CVE-2026-35160

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T15:15:15Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')