CVE-2021-36309
HIGHDell Enterprise SONiC OS <3.3.0 - Info Disclosure
Title source: llmDescription
Dell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vulnerability. An authenticated malicious user with access to the system may use the TACACS\Radius credentials stored to read sensitive information and use it in further attacks.
Scores
CVSS v3
7.1
EPSS
0.0026
EPSS Percentile
49.0%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-522
CWE-256
Status
published
Affected Products (1)
dell/enterprise_sonic_os
< 3.3.0
Timeline
Published
Oct 01, 2021
Tracked Since
Feb 18, 2026