DSA-2025-160: Security Update for Dell Networking OS10 Vulnerabilities
Summary: Dell Networking OS10 remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
High
Details
|
Third-party Component |
CVEs |
More Information |
|
redis |
CVE-2022-35977, CVE-2022-36021, CVE-2023-25155, CVE-2024-31228, CVE-2024-31449, CVE-2024-46981 |
|
|
busybox |
CVE-2021-28831, CVE-2021-42378, CVE-2021-42379, CVE-2021-42380, CVE-2021-42381, CVE-2021-42382, CVE-2021-42384, CVE-2021-42385, CVE-2021-42386, CVE-2022-48174, CVE-2023-42364, CVE-2023-42365 |
|
|
bind9 |
CVE-2024-11187 |
|
|
python-urllib3 |
CVE-2024-37891 |
|
|
libxml2 |
CVE-2022-49043, CVE-2023-39615, CVE-2023-45322, CVE-2024-25062, CVE-2024-56171, CVE-2025-24928, CVE-2025-27113 |
|
|
krb5 |
CVE-2025-24528 |
|
|
libtasn1-6 |
CVE-2024-12133 |
|
|
python2.7 |
CVE-2023-27043, CVE-2024-0397, CVE-2024-6232, CVE-2024-6923, CVE-2024-7592, CVE-2024-11168, CVE-2025-0938 |
|
|
gnutls28 |
CVE-2024-12243 |
|
|
freetype |
CVE-2025-27363 |
|
|
libxslt |
CVE-2024-55549, CVE-2025-24855 |
|
|
avahi |
CVE-2023-1981, CVE-2023-38469, CVE-2023-38470, CVE-2023-38471, CVE-2023-38472, CVE-2023-38473 |
|
|
pkix-ssh (OpenSSH) |
CVE-2025-26465, CVE-2025-26466 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2025-30103 |
Dell SmartFabric OS10 Software, version(s) prior to 10.5.6.9, contain(s) a Files or Directories Accessible to External Parties vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker. |
5.5 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2025-30103 |
Dell SmartFabric OS10 Software, version(s) prior to 10.5.6.9, contain(s) a Files or Directories Accessible to External Parties vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker. |
5.5 |
Affected Products & Remediation
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell Networking OS10 |
Versions prior to 10.5.6.9 |
Version 10.5.6.9 |
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell Networking OS10 |
Versions prior to 10.5.6.9 |
Version 10.5.6.9 |
- SmartFabric OS10 downloads are also available from your Dell Digital Locker.
- The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2025-05-21 |
Initial Release |
Acknowledgements
CVE-2025-30103: Dell would like to thank xiaohei from Ubisectech Sirius Team for reporting this issue.