GPU VulnDB

Database/Firmware, BMC & network fabric

Dell SmartFabric OS10 (XML external entity): XXE in SmartFabric OS10 before 10.6.0.5, reachable remotely

CVE-2025-36608Firmware, BMC & network fabriccurated

Impact

XXE in SmartFabric OS10 before 10.6.0.5, reachable remotely by a low-privileged attacker. XXE on a switch typically yields file read from the switch's filesystem — which holds the running configuration, and therefore the fabric's secrets and its full topology.

Who can reach it

Low-privileged attacker with remote access to the OS10 management interface.

What to do

Upgrade OS10 to 10.6.0.5 or later plus reload. Related file-exposure issue in the same release: CVE-2025-30103.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.