CVE-2026-63696
moderateCode Execution via Unverified Download in Dell SmartFabric OS10 (<10.6.1.3)
Dell SmartFabric OS10 versions prior to 10.6.1.3 download code without performing an integrity check, a CWE-494 flaw rated critical (CVSS 9.1). A remotely connected attacker who already holds high privileges (e.g., an authenticated admin on the switch) can supply a malicious code artifact that the device accepts and executes because its integrity is never validated. Successful exploitation yields code execution with a changed scope, meaning the compromise can extend beyond the initial switch context to the underlying system. This affects Dell PowerSwitch data center switches running SmartFabric OS10 before 10.6.1.3. No public proof of concept is known and the flaw is not in the CISA KEV catalog, so no in-the-wild exploitation has been reported.
What to do: Upgrade SmartFabric OS10 to version 10.6.1.3 or later as soon as possible. Until patched, strictly restrict management-plane access (SSH/HTTPS/API) to trusted admin networks, enforce multi-factor or bastion-mediated admin access, and rotate high-privilege switch credentials. Review switch logs and configuration history for unexpected image, package, or firmware download attempts.
| Dell SmartFabric OS10 Software | prior to 10.6.1.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
- Weakness
- CWE-494
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.