CVE-2021-36309: High severity dell enterprise sonic vulnerability
Dell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vulnerability. An authenticated malicious user with access to the system may use the TACACS\Radius credentials stored to read sensitive information and use it in further attacks.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36309?
CVE-2021-36309 is classified as a sensitive information disclosure vulnerability.
How do I fix CVE-2021-36309?
To remediate CVE-2021-36309, update Dell Enterprise SONiC OS to a version later than 3.3.0.
Who is affected by CVE-2021-36309?
CVE-2021-36309 affects systems running Dell Enterprise SONiC OS version 3.3.0 and earlier.
What is the impact of CVE-2021-36309?
The impact of CVE-2021-36309 is that an authenticated malicious user can access sensitive information such as TACACS/RADIUS credentials.
Can CVE-2021-36309 be exploited remotely?
CVE-2021-36309 requires local authenticated access to the system, so it cannot be exploited remotely.