Database/Firmware, BMC & network fabric
Dell SmartFabric OS10 (hard-coded password): A hard-coded password in OS10 10.5.6.x gives an unauthenticated attacker
CVE-2024-48831Firmware, BMC & network fabriccurated
Impact
A hard-coded password in OS10 10.5.6.x gives an unauthenticated attacker with local access full unauthorized access to the switch. Hard-coded means you cannot rotate it - only the patch removes it.
Who can reach it
Local access to the switch (console, or a compromised management host).
What to do
Upgrade OS10 per DSA-2025-068. Because the credential is hard-coded, there is no config-level mitigation - the firmware upgrade and reboot is the only fix.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.