Code Injection Vulnerability in Dell SmartFabric OS10 Software
CVE-2024-48829
6.7MEDIUM
What is CVE-2024-48829?
Dell SmartFabric OS10 Software contains a vulnerability that allows a high privileged attacker with local access to exploit the system through code injection. This flaw can potentially lead to unauthorized code execution within the affected software, compromising the integrity and security of the system. Users are urged to update to version 10.6.1.0 or later to mitigate this risk.
Affected Version(s)
SmartFabric OS10 Software < 10.6.1.0
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dell would like to thank n3k from TIANGONG Team of Legendsec at QI-ANXIN Group for reporting this issue.