First published: Fri Oct 01 2021(Updated: )
Dell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vulnerability. An authenticated malicious user with access to the system may use the TACACS\Radius credentials stored to read sensitive information and use it in further attacks.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Enterprise SONiC | <=3.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36309 is classified as a sensitive information disclosure vulnerability.
To remediate CVE-2021-36309, update Dell Enterprise SONiC OS to a version later than 3.3.0.
CVE-2021-36309 affects systems running Dell Enterprise SONiC OS version 3.3.0 and earlier.
The impact of CVE-2021-36309 is that an authenticated malicious user can access sensitive information such as TACACS/RADIUS credentials.
CVE-2021-36309 requires local authenticated access to the system, so it cannot be exploited remotely.