CVE-2026-63695
moderateUnauthenticated Session Fixation in Dell SmartFabric OS10 Could Allow Session Theft
Dell SmartFabric OS10 Software, in all versions prior to 10.6.1.3, contains a session fixation vulnerability (CWE-284, improper access control) that is rated critical with a CVSS 3.1 base score of 9.8. An unauthenticated attacker with remote access to an affected switch could fixate or predict a session identifier and use it to hijack an authenticated session, gaining the privileges of the legitimate administrator and impacting confidentiality, integrity, and availability of the managed fabric. The flaw affects the management plane of Dell PowerSwitch data center switches running OS10 and any Dell infrastructure stacks (such as VxRail/VxBlock-style deployments) built on SmartFabric OS10. No public proof-of-concept is known and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, so there is no evidence of in-the-wild exploitation at this time.
What to do: Upgrade SmartFabric OS10 to version 10.6.1.3 or later as soon as possible. Until patched, restrict switch management interfaces (SSH/HTTPS/API) to trusted administrative networks or VPN-only access via ACLs and firewall rules, and review authentication and session logs for unexplained session identifiers or concurrent administrative sessions. Verify that sessions are invalidated and regenerated after authentication following the upgrade.
| Dell SmartFabric OS10 Software | all versions prior to 10.6.1.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.