CVE-2021-36309

Dell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vulnerability. An authenticated malicious user with access to the system may use the TACACS\Radius credentials stored to read sensitive information and use it in further attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:o:dell:enterprise_sonic_os:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:13

Type Values Removed Values Added
CVSS v2 : 4.0
v3 : 6.5
v2 : 4.0
v3 : 7.1
References () https://www.dell.com/support/kbdoc/en-us/000191690/DSA-2021-190-Dell-Enterprise-SONiC-OS-Security-Update-for-an-information-disclosure-Vulnerability - Patch, Vendor Advisory () https://www.dell.com/support/kbdoc/en-us/000191690/DSA-2021-190-Dell-Enterprise-SONiC-OS-Security-Update-for-an-information-disclosure-Vulnerability - Patch, Vendor Advisory

25 Oct 2022, 14:58

Type Values Removed Values Added
CWE CWE-200 CWE-522

08 Oct 2021, 15:09

Type Values Removed Values Added
CPE cpe:2.3:o:dell:enterprise_sonic_os:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 6.5
CWE CWE-200
References (MISC) https://www.dell.com/support/kbdoc/en-us/000191690/DSA-2021-190-Dell-Enterprise-SONiC-OS-Security-Update-for-an-information-disclosure-Vulnerability - (MISC) https://www.dell.com/support/kbdoc/en-us/000191690/DSA-2021-190-Dell-Enterprise-SONiC-OS-Security-Update-for-an-information-disclosure-Vulnerability - Patch, Vendor Advisory

01 Oct 2021, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-01 21:15

Updated : 2024-11-21 06:13


NVD link : CVE-2021-36309

Mitre link : CVE-2021-36309

CVE.ORG link : CVE-2021-36309


JSON object : View

Products Affected

dell

  • enterprise_sonic_os
CWE
CWE-256

Unprotected Storage of Credentials

CWE-522

Insufficiently Protected Credentials