ZeroHour

CVE-2026-63696

moderate

Code Execution via Unverified Download in Dell SmartFabric OS10 (<10.6.1.3)

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

Dell SmartFabric OS10 versions prior to 10.6.1.3 download code without performing an integrity check, a CWE-494 flaw rated critical (CVSS 9.1). A remotely connected attacker who already holds high privileges (e.g., an authenticated admin on the switch) can supply a malicious code artifact that the device accepts and executes because its integrity is never validated. Successful exploitation yields code execution with a changed scope, meaning the compromise can extend beyond the initial switch context to the underlying system. This affects Dell PowerSwitch data center switches running SmartFabric OS10 before 10.6.1.3. No public proof of concept is known and the flaw is not in the CISA KEV catalog, so no in-the-wild exploitation has been reported.

What to do: Upgrade SmartFabric OS10 to version 10.6.1.3 or later as soon as possible. Until patched, strictly restrict management-plane access (SSH/HTTPS/API) to trusted admin networks, enforce multi-factor or bastion-mediated admin access, and rotate high-privilege switch credentials. Review switch logs and configuration history for unexpected image, package, or firmware download attempts.

Affected
Dell SmartFabric OS10 Softwareprior to 10.6.1.3
Estimated exposure
moderate≈1,000–10,000+ affected switch nodes (rough estimate; no public count) — SmartFabric OS10 runs on Dell PowerSwitch enterprise/data-center switches that are broadly but not mass-market deployed, and their management planes are typically reachable only from internal networks rather than the open internet, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

Weakness
CWE-494
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.