Home

Description

Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Control of Generation of Code ('Code Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.

PUBLISHED Reserved 2024-10-08 | Published 2025-11-12 | Updated 2025-11-13 | Assigner dell




MEDIUM: 6.7CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-94: Improper Control of Generation of Code ('Code Injection')

Product status

Default status
unaffected

Any version before 10.6.1.0
affected

Credits

Dell would like to thank n3k from TIANGONG Team of Legendsec at QI-ANXIN Group for reporting this issue. finder

References

www.dell.com/...ate-for-dell-networking-os10-vulnerabilities vendor-advisory

cve.org (CVE-2024-48829)

nvd.nist.gov (CVE-2024-48829)

Download JSON