Database/Firmware, BMC & network fabric
Dell SmartFabric Storage Software (restricted shell in SSH): TENANT ISOLATION: OS command injection escaping
Impact
TENANT ISOLATION: OS command injection escaping the restricted shell of the NVMe-oF fabric controller, from an authenticated remote user. Escaping the restricted shell gives full control of the appliance that enforces which host can attach to which NVMe namespace — the storage equivalent of owning the fabric's ACLs. Related CLI and path-traversal issues: CVE-2023-43069, CVE-2023-43070, CVE-2023-4401.
Who can reach it
Authenticated remote user with SSH access to SmartFabric Storage Software v1.4 or earlier.
What to do
Upgrade SmartFabric Storage Software past v1.4 — appliance software upgrade plus restart. Restrict SSH to a management bastion, and audit the NVMe-oF zoning/namespace-masking configuration afterwards rather than assuming the patch is sufficient.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.