PT-2021-14566 · Dell Emc · Dell Networking X-Series+1

Ken Pyle

·

Published

2021-04-30

·

Updated

2021-05-10

·

CVE-2021-21507

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell EMC Networking X-Series versions prior to 3.0.1.8 Dell EMC PowerEdge VRTX Switch Module versions prior to 2.0.0.82
Description The issue is related to weak password encryption, allowing a remote unauthenticated attacker to potentially exploit it and disclose certain user credentials. The exposed credentials could be used to access the system with the privileges of the compromised account.
Recommendations For Dell EMC Networking X-Series versions prior to 3.0.1.8, update to version 3.0.1.8 or later to resolve the issue. For Dell EMC PowerEdge VRTX Switch Module versions prior to 2.0.0.82, update to version 2.0.0.82 or later to resolve the issue.

Fix

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21507

Affected Products

Dell Networking X-Series
Dell Emc Poweredge Vrtx Switch Module