CVE-2022-29089
MEDIUMDell Networking OS10 - Info Disclosure
Title source: llmDescription
Dell Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an information disclosure vulnerability. A remote, unauthenticated attacker could potentially exploit this vulnerability by reverse engineering to retrieve sensitive information and access the REST API with admin privileges.
Scores
CVSS v3
6.4
EPSS
0.0019
EPSS Percentile
40.7%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
Classification
CWE
CWE-522
Status
published
Affected Products (1)
dell/smartfabric_os10
< 10.5.1.11
Timeline
Published
Sep 28, 2022
Tracked Since
Feb 18, 2026