Description
Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Published: 2026-09-03
Score: 5 Medium
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell SmartFabric OS10 Software versions prior to 10.5.6.14 contain a command injection flaw (CWE-77). Based on the description, it is inferred that a high privileged attacker who can access the system remotely could inject and execute arbitrary OS commands. The vulnerability allows the attacker to compromise the integrity and availability of the affected device.

Affected Systems

Dell SmartFabric OS10 devices running firmware before version 10.5.6.14 are affected. Based on the description, it is inferred that the flaw targets systems exposed to remote management interfaces that allow privileged users to issue commands.

Risk and Exploitability

The CVSS score of 5 indicates a moderate risk level. The EPSS score is 1%, indicating a modest exploit probability, and the vulnerability is not listed in the CISA KEV catalog. The attack requires remote access with high privileges; compromise of remote management credentials is the primary prerequisite. Once exploited, an attacker can gain full command execution capabilities on the device.

Generated by OpenCVE AI on September 4, 2026 at 15:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Dell SmartFabric OS10 Security Update dsa-2026-322 to upgrade to version 10.5.6.14 or later.
  • Disable remote command execution for non-essential accounts and restrict privileged management access to trusted network segments.
  • Enable logging and monitoring of all command execution attempts to detect and respond to potential exploitation.

Generated by OpenCVE AI on September 4, 2026 at 15:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Title Dell SmartFabric OS10 Command Injection Vulnerability

Thu, 03 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Dell SmartFabric OS10 Command Injection Vulnerability
First Time appeared Dell
Dell smartfabric Os10
Vendors & Products Dell
Dell smartfabric Os10

Thu, 03 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Weaknesses CWE-77
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Dell Smartfabric Os10
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-04T03:56:02.784Z

Reserved: 2026-07-17T17:05:09.170Z

Link: CVE-2026-63694

cve-icon Vulnrichment

Updated: 2026-09-03T14:46:00.547Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-03T15:17:31.680

Modified: 2026-09-04T04:17:59.113

Link: CVE-2026-63694

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T16:00:05Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')