PT-2021-14566 · Dell Emc · Dell Networking X-Series+1
Ken Pyle
·
Published
2021-04-30
·
Updated
2021-05-10
·
CVE-2021-21507
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell EMC Networking X-Series versions prior to 3.0.1.8
Dell EMC PowerEdge VRTX Switch Module versions prior to 2.0.0.82
Description
The issue is related to weak password encryption, allowing a remote unauthenticated attacker to potentially exploit it and disclose certain user credentials. The exposed credentials could be used to access the system with the privileges of the compromised account.
Recommendations
For Dell EMC Networking X-Series versions prior to 3.0.1.8, update to version 3.0.1.8 or later to resolve the issue.
For Dell EMC PowerEdge VRTX Switch Module versions prior to 2.0.0.82, update to version 2.0.0.82 or later to resolve the issue.
Fix
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dell Networking X-Series
Dell Emc Poweredge Vrtx Switch Module