CVE-2021-36309

Dell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vulnerability. An authenticated malicious user with access to the system may use the TACACS\Radius credentials stored to read sensitive information and use it in further attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:o:dell:enterprise_sonic_os:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:13

Type Values Removed Values Added
CVSS v2 : 4.0
v3 : 6.5
v2 : 4.0
v3 : 7.1
References () https://www.dell.com/support/kbdoc/en-us/000191690/DSA-2021-190-Dell-Enterprise-SONiC-OS-Security-Update-for-an-information-disclosure-Vulnerability - Patch, Vendor Advisory () https://www.dell.com/support/kbdoc/en-us/000191690/DSA-2021-190-Dell-Enterprise-SONiC-OS-Security-Update-for-an-information-disclosure-Vulnerability - Patch, Vendor Advisory

Information

Published : 2021-10-01 21:15

Updated : 2024-11-21 06:13


NVD link : CVE-2021-36309

Mitre link : CVE-2021-36309

CVE.ORG link : CVE-2021-36309


JSON object : View

Products Affected

dell

  • enterprise_sonic_os
CWE
CWE-256

Plaintext Storage of a Password

CWE-522

Insufficiently Protected Credentials