Impact
Dell SmartFabric OS10 Software allows a code download without performing an integrity check. The defective check can be triggered by a high‑privileged attacker who has remote access to the device, enabling execution of arbitrary code. The likely attack vector is a high‑privileged remote attacker exploiting this flaw. This weakness can directly compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
Vendor Dell provides the SmartFabric OS10 operating system for its networking gear. All releases prior to version 10.6.1.3 are affected. Users running those older releases must verify their installed firmware version and apply the recommended update if still on a vulnerable build.
Risk and Exploitability
The CVSS score of 9.1 places this issue in the high‑to‑critical severity range. Enterprise exposure is significant because the vulnerability requires remote, high‑privileged lines of attack that are commonly present in network management environments, and the absence of an integrity check makes the flaw amenable to exploitation even with limited credentials. The EPSS score, which is less than 1%, indicates a very low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker could act remotely with high privileges. Nevertheless, the high CVSS and the nature of the weakness recommend treating it as a likely threat vector, especially in environments where network management interfaces are reachable from outside the trusted network.
OpenCVE Enrichment