DSA-2026-322: Security Update for Dell Networking OS10 Vulnerabilities
Riepilogo: Dell Networking OS10 remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impatto
Critical
Dettagli
|
Third-party Component |
CVEs |
More Information |
|
go standard library |
CVE-2025-61729 |
|
|
glibc, encoding/pem, net/url, encoding/asn1, crypto/tls, database/sql, net/textproto, crypto/x509 |
CVE-2025-47912, CVE-2025-58185, CVE-2025-58189, CVE-2025-47907 |
|
|
golang |
CVE-2025-61726, CVE-2025-61730, CVE-2025-68121, CVE-2025-61727, CVE-2025-61729 |
|
|
pyjwt |
CVE-2026-32597 |
|
|
inetutils |
CVE-2026-32746 |
|
|
bind9 |
CVE-2025-40778 |
|
|
pkix-ssh |
CVE-2026-35386, CVE-2026-35385, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414 |
|
|
systemd |
CVE-2026-4105, CVE-2026-29111, CVE-2026-40225, CVE-2026-40226 |
|
|
nginx |
CVE-2026-42945, CVE-2026-42946, CVE-2026-40701, CVE-2026-42934, CVE-2026-40460, CVE-2025-53859, CVE-2026-1642, CVE-2026-9256, CVE-2026-27651, CVE-2026-27654, CVE-2026-27784, CVE-2026-28753, CVE-2026-32647 |
|
|
pyasn1 |
CVE-2026-30922 |
|
|
python-gevent |
CVE-2023-41419 |
|
|
gnutls28 |
CVE-2026-3833, CVE-2026-5260, CVE-2026-33845, CVE-2026-33846, CVE-2026-42009, CVE-2026-42011, CVE-2026-42012, CVE-2026-42013, CVE-2026-42014, CVE-2026-42015 |
|
|
nghttp2 |
CVE-2026-27135 |
|
|
libxml2 |
CVE-2025-8732, CVE-2026-0989, CVE-2026-0990, CVE-2026-0992, CVE-2026-1757 |
|
|
libhtml-parser-perl |
CVE-2026-8829 |
|
|
curl |
CVE-2026-3805, CVE-2025-13034, CVE-2024-11053, CVE-2025-10148, CVE-2025-0167, CVE-2025-14819 |
|
|
libexpat |
CVE-2024-50602, CVE-2022-40674, CVE-2024-45492, CVE-2024-45491, CVE-2024-45490, CVE-2022-23990, CVE-2022-43680, CVE-2023-52425 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-35160 |
Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
5.0 |
|
|
CVE-2026-61417 |
Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. |
6.5 |
|
|
CVE-2026-61418 |
Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
7.5 |
|
|
CVE-2026-63694 |
Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
5.0 |
|
|
CVE-2026-63695 |
Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft. |
9.8 |
|
|
CVE-2026-63696 |
Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. |
9.1 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-35160 |
Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
5.0 |
|
|
CVE-2026-61417 |
Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. |
6.5 |
|
|
CVE-2026-61418 |
Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
7.5 |
|
|
CVE-2026-63694 |
Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
5.0 |
|
|
CVE-2026-63695 |
Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft. |
9.8 |
|
|
CVE-2026-63696 |
Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. |
9.1 |
Prodotti interessati e correzione
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell Networking OS10 |
Versions prior to 10.5.6.14 |
Version 10.5.6.14 |
|
Product |
Affected Versions |
Remediated Versions |
Link |
|
Dell Networking OS10 |
Versions prior to 10.5.6.14 |
Version 10.5.6.14 |
- SmartFabric OS10 downloads are also available from My Account.
- The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
Cronologia delle revisioni
|
Revision |
Date |
Description |
|
1.0 |
2026-08-20 |
Initial Release |
Ringraziamenti
- CVE-2026-35160: Dell would like to thank kkking for reporting this issue.
- CVE-2026-61417: Dell would like to thank saltedfish for reporting this issue.
- CVE-2026-61418: Dell would like to thank Huynh Dinh Vu (WinD39) and Huynh Dinh Van for reporting this issue.
- CVE-2026-63694: Dell would like to thank kkking for reporting this issue.
- CVE-2026-63695: Dell would like to thank WinD39 - Huynh Dinh Vu for reporting this issue.
- CVE-2026-63696: Dell would like to thank Haxship1337 (Huynh Dinh Van) and WinD39 (Huynh Dinh Vu) for reporting this issue.