Description
Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Published: 2026-09-17
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

Dell SmartFabric Manager exposes a weakness where insufficient permissions are not properly checked, allowing an attacker with low-level access to read sensitive data. This Improper Handling of Insufficient Permissions or Privileges flaw (CWE-280) can lead to information disclosure without causing denial of service or code execution.

Affected Systems

The vulnerability affects Dell SmartFabric Manager versions earlier than 2.2.1. Any deployment running a pre‑2.2.1 build is susceptible, regardless of environment.

Risk and Exploitability

The CVSS score of 3.5 indicates a low severity level. No EPSS value is available and the issue is not listed in CISA KEV. A likely attack requires the attacker to have remote connectivity to the SmartFabric Manager service and to operate with low privileges; from that position they can trigger the flaw and retrieve data. The likelihood of exploitation is considered low, but the potential for confidential data exposure remains.

Generated by OpenCVE AI on September 17, 2026 at 21:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Dell’s security update to upgrade to SmartFabric Manager 2.2.1 or later
  • Restrict network access to the SmartFabric Manager interfaces to only trusted management hosts
  • Regularly audit and enforce least privilege roles, removing any unnecessary permissions

Generated by OpenCVE AI on September 17, 2026 at 21:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Insufficient Permissions in Dell SmartFabric Manager

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell smartfabric Manager
Vendors & Products Dell
Dell smartfabric Manager

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Weaknesses CWE-280
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

Dell Smartfabric Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-17T15:19:34.373Z

Reserved: 2026-06-15T16:28:29.012Z

Link: CVE-2026-54471

cve-icon Vulnrichment

Updated: 2026-09-17T15:19:29.592Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-17T15:16:47.910

Modified: 2026-09-18T17:55:19.340

Link: CVE-2026-54471

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-280

    Improper Handling of Insufficient Permissions or Privileges