Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to execution of commands with elevated privileges.
CVE ID: CVE-2025-22472
CVSS Base Severity: HIGH
CVSS Base Score: 7.8
CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendor: Dell
Product: SmartFabric OS10 Software
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 11.43% (scored less or equal to compared to others)
EPSS Date: 2025-04-15 (when was this score calculated)