Command Injection Vulnerability in Dell SmartFabric OS10 Software
CVE-2024-48017

6.5MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
17 March 2025

Summary

Dell SmartFabric OS10 Software versions 10.5.4.x, 10.5.5.x, 10.5.6.x, and 10.6.0.x are susceptible to a command injection vulnerability. This flaw allows a highly privileged attacker with remote access to execute arbitrary code, potentially compromising the integrity and functionality of the system. Organizations using these versions should prioritize applying the latest security updates and following best practices for mitigation to safeguard their networks. For more information and remediation guidance, refer to the vendor's security advisories.

Affected Version(s)

SmartFabric OS10 Software 10.5.4.x

SmartFabric OS10 Software 10.5.5.x

SmartFabric OS10 Software 10.5.6.x

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell would like to thank n3k from TIANGONG Team of Legendsec at QI-ANXIN Group for reporting this issue.
.