CVE-2021-36309

HIGH

Dell Enterprise SONiC OS <3.3.0 - Info Disclosure

Title source: llm

Description

Dell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vulnerability. An authenticated malicious user with access to the system may use the TACACS\Radius credentials stored to read sensitive information and use it in further attacks.

Scores

CVSS v3 7.1
EPSS 0.0026
EPSS Percentile 49.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-522 CWE-256
Status published

Affected Products (1)

dell/enterprise_sonic_os < 3.3.0

Timeline

Published Oct 01, 2021
Tracked Since Feb 18, 2026