PT-2021-21221 · Dell · Os10
Published
2021-11-20
·
Updated
2021-11-23
·
CVE-2021-36319
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Dell Networking OS10 versions 10.4.3.x through 10.5.1.x
Description
The issue allows a low privileged authenticated malicious user to gain access to SNMP authentication failure messages, potentially exposing sensitive information.
Recommendations
For versions 10.4.3.x, 10.5.0.x, and 10.5.1.x, consider restricting access to SNMP authentication failure messages until a patch is available.
As a temporary workaround, limit the privileges of authenticated users to minimize the risk of exploitation.
Avoid using low-privileged accounts for critical operations in the affected versions until the issue is resolved.
Fix
Improper Initialization
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Os10