CVE-2021-21507
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Dell EMC Networking X-Series firmware versions prior to 3.0.1.8 and Dell EMC PowerEdge VRTX Switch Module firmware versions prior to 2.0.0.82 contain a Weak Password Encryption Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable system with privileges of the compromised account.
Affected (11)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.0.1.8 |
| Running on/with | Platform Versions |
|---|---|
Dell X1008p | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.0.1.8 |
| Running on/with | Platform Versions |
|---|---|
Dell X1018p | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.0.1.8 |
| Running on/with | Platform Versions |
|---|---|
Dell X1026p | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.0.1.8 |
| Running on/with | Platform Versions |
|---|---|
Dell X1052p | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.0.1.8 |
| Running on/with | Platform Versions |
|---|---|
Dell X4012 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0.0.82 |
| Running on/with | Platform Versions |
|---|---|
Dell R1 2401 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0.0.82 |
| Running on/with | Platform Versions |
|---|---|
Dell R1 2210 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.0.1.8 |
| Running on/with | Platform Versions |
|---|---|
Dell X1008 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.0.1.8 |
| Running on/with | Platform Versions |
|---|---|
Dell X1018 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.0.1.8 |
| Running on/with | Platform Versions |
|---|---|
Dell X1026 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.0.1.8 |
| Running on/with | Platform Versions |
|---|---|
Dell X1052 | All versions |
Related CWEs
CWE-261
Weak Encoding for Password
Obscuring a password with a trivial encoding does not protect the password.
CWE-326
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.