Home

Description

Dell SmartFabric OS10 Software, versions prior to 10.5.6.12, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

PUBLISHED Reserved 2026-01-07 | Published 2026-02-17 | Updated 2026-02-18 | Assigner dell




MEDIUM: 6.6CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')

Product status

Default status
unaffected

Any version before 10.5.6.12
affected

Credits

Dell would like to thank kkking for reporting this issue finder

References

www.dell.com/...ate-for-dell-networking-os10-vulnerabilities vendor-advisory

cve.org (CVE-2026-22284)

nvd.nist.gov (CVE-2026-22284)

Download JSON