Description
Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Session Hijacking
Action: Immediate Patch
AI Analysis

Impact

Dell SmartFabric OS10 Software versions below 10.6.1.3 are vulnerable to a session fixation flaw. An unauthenticated attacker can set a session identifier before the user logs in, allowing the attacker to hijack that session after the target authenticates. This results in session theft, permitting the attacker to impersonate the user and access the network infrastructure with the same privileges, potentially leading to unauthorized configuration changes or data exposure. The weakness maps to CWE-284, highlighting the improper handling of authentication states.

Affected Systems

The affected product is Dell SmartFabric OS10 Software. All releases earlier than version 10.6.1.3 are impacted. Systems running any of those pre-10.6.1.3 builds must be considered vulnerable until patched.

Risk and Exploitability

The CVSS score of 9.8 classifies this as Critical. The EPSS score is <1%, indicating a very low but non‑zero exploitation probability, yet the CVSS reflects a high exploitation likelihood over a remote network. The flaw is unauthenticated and remote, meaning an attacker with network access to the device could exploit it without prior. The vulnerability is not listed in CISA KEV, yet its severity and the nature of the flaw make it likely to be targeted in the wild.

Generated by OpenCVE AI on September 20, 2026 at 17:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Dell's OS10 update version 10.6.1.3 or later to remove the session fixation flaw.
  • Limit exposure of management interfaces by restricting access to trusted IP ranges or implementing VLAN segmentation.
  • Monitor for abnormal session activity by enabling audit logs and reviewing session logs for repeated login attempts or unexpected session identifiers.

Generated by OpenCVE AI on September 20, 2026 at 17:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Dell SmartFabric OS10 Session Fixation Vulnerability

Thu, 17 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Dell SmartFabric OS10 Session Fixation Vulnerability

Tue, 15 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell smartfabric Os10 Software
Vendors & Products Dell
Dell smartfabric Os10 Software

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Smartfabric Os10 Software
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-16T03:56:25.069Z

Reserved: 2026-07-17T17:05:09.170Z

Link: CVE-2026-63695

cve-icon Vulnrichment

Updated: 2026-09-15T15:22:27.376Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T15:17:20.390

Modified: 2026-09-16T20:37:16.870

Link: CVE-2026-63695

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:30:18Z

Weaknesses