Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-21507


Dell EMC Networking X-Series firmware versions prior to 3.0.1.8 and Dell EMC PowerEdge VRTX Switch Module firmware versions prior to 2.0.0.82 contain a Weak Password Encryption Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable system with privileges of the compromised account.


Published

2021-04-30T21:15:08.597

Last Modified

2024-11-21T05:48:30.070

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-261
  • Type: Primary
    CWE-326

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System dell x1008p_firmware < 3.0.1.8 Yes
Hardware dell x1008p - No
Operating System dell x1018p_firmware < 3.0.1.8 Yes
Hardware dell x1018p - No
Operating System dell x1026p_firmware < 3.0.1.8 Yes
Hardware dell x1026p - No
Operating System dell x1052p_firmware < 3.0.1.8 Yes
Hardware dell x1052p - No
Operating System dell x4012_firmware < 3.0.1.8 Yes
Hardware dell x4012 - No
Operating System dell r1-2401_firmware < 2.0.0.82 Yes
Hardware dell r1-2401 - No
Operating System dell r1-2210_firmware < 2.0.0.82 Yes
Hardware dell r1-2210 - No
Operating System dell x1008_firmware < 3.0.1.8 Yes
Hardware dell x1008 - No
Operating System dell x1018_firmware < 3.0.1.8 Yes
Hardware dell x1018 - No
Operating System dell x1026_firmware < 3.0.1.8 Yes
Hardware dell x1026 - No
Operating System dell x1052_firmware < 3.0.1.8 Yes
Hardware dell x1052 - No

References