CVE-2021-36309

HIGH

Dell Enterprise SONiC OS <3.3.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Dell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vulnerability. An authenticated malicious user with access to the system may use the TACACS\Radius credentials stored to read sensitive information and use it in further attacks.

Scores

CVSS v3 7.1
EPSS 0.0064
EPSS Percentile 47.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-256 CWE-522
Status published
Products (1)
dell/enterprise_sonic_os < 3.3.0
Published Oct 01, 2021
Tracked Since Feb 18, 2026