DSA-2026-032: Security Update for Dell Networking OS10 Vulnerabilities
Oversigt: Dell Networking OS10 remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Virkning
High
Oplysninger
|
Third-party Component |
CVEs |
More Information |
|
redis |
CVE-2025-46817, CVE-2025-46819, CVE-2025-49844 |
|
|
libfcgi |
CVE-2025-23016 |
|
|
libxml2 |
CVE-2025-9714, CVE-2025-7425 |
|
|
nginx |
CVE-2024-7347, CVE-2024-33452, CVE-2025-23419 |
|
|
libssh |
CVE-2020-16135, CVE-2023-6004, CVE-2023-6918 |
|
|
libpng1.6 |
CVE-2025-64505, CVE-2025-64506, CVE-2025-64720, CVE-2025-65018, CVE-2025-66293 |
|
|
glib2.0 |
CVE-2025-4373, CVE-2025-7039, CVE-2025-13601, CVE-2025-14087, CVE-2025-14512 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-22284 |
Dell SmartFabric OS10 Software, versions prior to 10.5.5.17, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
6.6 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-22284 |
Dell SmartFabric OS10 Software, versions prior to 10.5.5.17, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
6.6 |
Berørte produkter og udbedring
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell Networking OS10 |
Versions prior to 10.5.5.17 |
Version 10.5.5.17 |
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell Networking OS10 |
Versions prior to 10.5.5.17 |
Version 10.5.5.17 |
- SmartFabric OS10 downloads are also available from My Account.
- The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
Revisionshistorik
|
Revision |
Date |
Description |
|
1.0 |
2026-02-17 |
Initial Release |
|
2.0 |
2026-02-23 |
Removed CVE-2025-61984 as it is not applicable for the 10.5.5.17 release |
Bekræftelser
CVE-2026-22284: Dell would like to thank kkking for reporting this issue.