Database/Firmware, BMC & network fabric
Dell SmartFabric Storage Software: Improper input validation in Dell SmartFabric Storage Software 1.3 and lower
Impact
Improper input validation in Dell SmartFabric Storage Software 1.3 and lower, exploitable by a remote unauthenticated attacker. SmartFabric Storage Software is the NVMe-over-TCP fabric controller — it performs the discovery and zoning that decides which host initiators can see which NVMe subsystems. Compromising it is compromising the storage access-control layer for the whole cluster. Companion unauthenticated command injection: CVE-2022-31232.
Who can reach it
Unauthenticated, remote to the SmartFabric Storage Software service.
What to do
Upgrade the SmartFabric Storage Software appliance/VM past 1.3 (and past 1.4 for the CVE-2023-4306x set). Application upgrade with a service restart; NVMe-oF sessions reconnect. Afterwards, re-verify the zoning database against intent, because an attacker with control here would change exactly that.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.