Description
Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Dell SmartFabric OS10 Software allows a code download without performing an integrity check. The defective check can be triggered by a high‑privileged attacker who has remote access to the device, enabling execution of arbitrary code. The likely attack vector is a high‑privileged remote attacker exploiting this flaw. This weakness can directly compromise confidentiality, integrity, and availability of the affected system.

Affected Systems

Vendor Dell provides the SmartFabric OS10 operating system for its networking gear. All releases prior to version 10.6.1.3 are affected. Users running those older releases must verify their installed firmware version and apply the recommended update if still on a vulnerable build.

Risk and Exploitability

The CVSS score of 9.1 places this issue in the high‑to‑critical severity range. Enterprise exposure is significant because the vulnerability requires remote, high‑privileged lines of attack that are commonly present in network management environments, and the absence of an integrity check makes the flaw amenable to exploitation even with limited credentials. The EPSS score, which is less than 1%, indicates a very low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker could act remotely with high privileges. Nevertheless, the high CVSS and the nature of the weakness recommend treating it as a likely threat vector, especially in environments where network management interfaces are reachable from outside the trusted network.

Generated by OpenCVE AI on September 20, 2026 at 16:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Dell’s security update for SmartFabric OS10 to reach version 10.6.1.3 or later.
  • If an immediate update is not possible, block or restrict remote privileged access to the device’s management interfaces to prevent the ability to trigger the download.
  • Configure network segmentation or firewall rules to isolate the SmartFabric OS10 hardware from untrusted hosts, and monitor logs for unexpected code‑download events.

Generated by OpenCVE AI on September 20, 2026 at 16:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Download of Code Without Integrity Check in Dell SmartFabric OS10 Enables Remote Code Execution

Thu, 17 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Unverified Code Download on Dell SmartFabric OS10

Wed, 16 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Unverified Code Download on Dell SmartFabric OS10

Tue, 15 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell smartfabric Os10 Software
Vendors & Products Dell
Dell smartfabric Os10 Software

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
Weaknesses CWE-494
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Dell Smartfabric Os10 Software
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-16T03:56:26.518Z

Reserved: 2026-07-17T17:05:09.170Z

Link: CVE-2026-63696

cve-icon Vulnrichment

Updated: 2026-09-15T15:23:21.647Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T15:17:20.527

Modified: 2026-09-16T20:37:16.870

Link: CVE-2026-63696

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:00:13Z

Weaknesses
  • CWE-494

    Download of Code Without Integrity Check