PT-2021-21221 · Dell · Os10

Published

2021-11-20

·

Updated

2021-11-23

·

CVE-2021-36319

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dell Networking OS10 versions 10.4.3.x through 10.5.1.x
Description The issue allows a low privileged authenticated malicious user to gain access to SNMP authentication failure messages, potentially exposing sensitive information.
Recommendations For versions 10.4.3.x, 10.5.0.x, and 10.5.1.x, consider restricting access to SNMP authentication failure messages until a patch is available. As a temporary workaround, limit the privileges of authenticated users to minimize the risk of exploitation. Avoid using low-privileged accounts for critical operations in the affected versions until the issue is resolved.

Fix

Improper Initialization

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36319

Affected Products

Os10