CVE-2026-35160: OS Command Injection
Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell SmartFabric OS10 Softwareto a version that resolves this vulnerability.Fixed in 10.5.6.14
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
Exploitation requires a high-privileged attacker who already has remote access to the affected system. The attack complexity is rated high, and no user interaction is required.
Which versions should be prioritized for remediation?
Dell SmartFabric OS10 versions earlier than 10.5.6.14 are affected. Upgrade to 10.5.6.14 or a later available version.
What is the potential impact if exploitation succeeds?
A successful exploit could allow OS command execution. The reported impact includes high confidentiality impact and low integrity impact, with no availability impact listed.