CVE-2021-36309

Dell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vulnerability. An authenticated malicious user with access to the system may use the TACACS\Radius credentials stored to read sensitive information and use it in further attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:o:dell:enterprise_sonic_os:*:*:*:*:*:*:*:*

History

25 Oct 2022, 14:58

Type Values Removed Values Added
CWE CWE-200 CWE-522

08 Oct 2021, 15:09

Type Values Removed Values Added
CPE cpe:2.3:o:dell:enterprise_sonic_os:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 6.5
CWE CWE-200
References (MISC) https://www.dell.com/support/kbdoc/en-us/000191690/DSA-2021-190-Dell-Enterprise-SONiC-OS-Security-Update-for-an-information-disclosure-Vulnerability - (MISC) https://www.dell.com/support/kbdoc/en-us/000191690/DSA-2021-190-Dell-Enterprise-SONiC-OS-Security-Update-for-an-information-disclosure-Vulnerability - Patch, Vendor Advisory

01 Oct 2021, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-01 21:15

Updated : 2024-02-04 22:08


NVD link : CVE-2021-36309

Mitre link : CVE-2021-36309

CVE.ORG link : CVE-2021-36309


JSON object : View

Products Affected

dell

  • enterprise_sonic_os
CWE
CWE-522

Insufficiently Protected Credentials

CWE-256

Unprotected Storage of Credentials