Vulnerability Details CVE-2021-36309
Dell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vulnerability. An authenticated malicious user with access to the system may use the TACACS\Radius credentials stored to read sensitive information and use it in further attacks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.6%
CVSS Severity
CVSS v3 Score 7.1
CVSS v2 Score 4.0
Products affected by CVE-2021-36309
-
cpe:2.3:o:dell:enterprise_sonic_os:*