ZeroHour

CVE-2026-63695

moderate

Unauthenticated Session Fixation in Dell SmartFabric OS10 Could Allow Session Theft

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

Dell SmartFabric OS10 Software, in all versions prior to 10.6.1.3, contains a session fixation vulnerability (CWE-284, improper access control) that is rated critical with a CVSS 3.1 base score of 9.8. An unauthenticated attacker with remote access to an affected switch could fixate or predict a session identifier and use it to hijack an authenticated session, gaining the privileges of the legitimate administrator and impacting confidentiality, integrity, and availability of the managed fabric. The flaw affects the management plane of Dell PowerSwitch data center switches running OS10 and any Dell infrastructure stacks (such as VxRail/VxBlock-style deployments) built on SmartFabric OS10. No public proof-of-concept is known and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, so there is no evidence of in-the-wild exploitation at this time.

What to do: Upgrade SmartFabric OS10 to version 10.6.1.3 or later as soon as possible. Until patched, restrict switch management interfaces (SSH/HTTPS/API) to trusted administrative networks or VPN-only access via ACLs and firewall rules, and review authentication and session logs for unexplained session identifiers or concurrent administrative sessions. Verify that sessions are invalidated and regenerated after authentication following the upgrade.

Affected
Dell SmartFabric OS10 Softwareall versions prior to 10.6.1.3
Estimated exposure
moderatelikely on the order of 10,000-100,000 OS10-based switches deployed, with only a small fraction (likely low thousands) having management interfaces reachable… — Dell PowerSwitch switches running SmartFabric OS10 are a common choice in enterprise data centers and Dell converged/hyperconverged stacks, where a single deployment typically contains multiple switches, but management interfaces are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.