Impact
Dell SmartFabric OS10 Software versions below 10.6.1.3 are vulnerable to a session fixation flaw. An unauthenticated attacker can set a session identifier before the user logs in, allowing the attacker to hijack that session after the target authenticates. This results in session theft, permitting the attacker to impersonate the user and access the network infrastructure with the same privileges, potentially leading to unauthorized configuration changes or data exposure. The weakness maps to CWE-284, highlighting the improper handling of authentication states.
Affected Systems
The affected product is Dell SmartFabric OS10 Software. All releases earlier than version 10.6.1.3 are impacted. Systems running any of those pre-10.6.1.3 builds must be considered vulnerable until patched.
Risk and Exploitability
The CVSS score of 9.8 classifies this as Critical. The EPSS score is <1%, indicating a very low but non‑zero exploitation probability, yet the CVSS reflects a high exploitation likelihood over a remote network. The flaw is unauthenticated and remote, meaning an attacker with network access to the device could exploit it without prior. The vulnerability is not listed in CISA KEV, yet its severity and the nature of the flaw make it likely to be targeted in the wild.
OpenCVE Enrichment