First published: Sat Nov 20 2021(Updated: )
Networking OS10, versions prior to October 2021 with RESTCONF API enabled, contains a privilege escalation vulnerability. A malicious low privileged user with specific access to the API could potentially exploit this vulnerability to gain admin privileges on the affected system.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell SmartFabric OS10 | <10.4.3.8 | |
Dell SmartFabric OS10 | >=10.5.0.0<10.5.0.10 | |
Dell SmartFabric OS10 | >=10.5.1.0<10.5.1.10 | |
Dell SmartFabric OS10 | >=10.5.2.0<10.5.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36307 is classified as a high severity vulnerability due to its potential for privilege escalation.
To mitigate CVE-2021-36307, upgrade to Dell Networking OS10 version 10.4.3.8 or later.
CVE-2021-36307 affects users of Dell OS10 Networking Switches running versions prior to October 2021 with RESTCONF API enabled.
CVE-2021-36307 is a privilege escalation vulnerability.
Yes, a low privileged user with specific access to the RESTCONF API can exploit CVE-2021-36307 to gain admin privileges.