CVE-2021-36309

Dell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vulnerability. An authenticated malicious user with access to the system may use the TACACS\Radius credentials stored to read sensitive information and use it in further attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:o:dell:enterprise_sonic_os:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-10-01 21:15

Updated : 2024-02-28 18:48


NVD link : CVE-2021-36309

Mitre link : CVE-2021-36309

CVE.ORG link : CVE-2021-36309


JSON object : View

Products Affected

dell

  • enterprise_sonic_os
CWE
CWE-522

Insufficiently Protected Credentials

CWE-256

Plaintext Storage of a Password