CVE-2023-32462 CRITICAL

CVE-2023-32462

Vendor Dell
Product Dell SmartFabric OS10
Weakness CWE-20 · Input validation
Published February 15, 2024
Last update April 24, 2025

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Dell OS10 Networking Switches running 10.5.2.x and above contain an OS command injection vulnerability when using remote user authentication. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands and possible system takeover. This is a critical vulnerability as it allows an attacker to cause severe damage. Dell recommends customers to upgrade at the earliest opportunity.

Key dates

02Disclosure timeline

February 15, 2024 CVE published
April 24, 2025 Record updated