« Volver al listado

CVE-2021-36319

Estado: ModificadaBaja (3.3)—

Dell Networking OS10 versions 10.4.3.x, 10.5.0.x and 10.5.1.x contain an information exposure vulnerability. A low privileged authenticated malicious user can gain access to SNMP authentication failure messages.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-36319",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security_alert@emc.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.3,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.3,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "Dell",
          "product": "Dell Networking OS10",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "10.5.1.x",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-11-20T02:15:07.330",
  "references": [
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000193076",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000193076",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security_alert@emc.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-665"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-668"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Dell Networking OS10 versions 10.4.3.x, 10.5.0.x and 10.5.1.x contain an information exposure vulnerability. A low privileged authenticated malicious user can gain access to SNMP authentication failure messages."
    },
    {
      "lang": "es",
      "value": "Dell Networking OS10 versiones 10.4.3.x, 10.5.0.x y 10.5.1.x, contienen una vulnerabilidad de exposición de información. Un usuario malicioso con pocos privilegios puede conseguir acceso a los mensajes de fallo de autenticación de SNMP"
    }
  ],
  "lastModified": "2026-06-17T03:58:39.133",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dell:networking_os10:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "609D66D7-E699-4C3F-8970-F5AF1BCDD32F",
              "versionEndExcluding": "10.4.3.8"
            },
            {
              "criteria": "cpe:2.3:o:dell:networking_os10:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B651D680-C00D-4974-AB90-3036A4F50826",
              "versionEndExcluding": "10.5.0.10",
              "versionStartIncluding": "10.5.0.0"
            },
            {
              "criteria": "cpe:2.3:o:dell:networking_os10:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A8D3E1F-3ECC-4523-862D-497A94DA030C",
              "versionEndExcluding": "10.5.1.10",
              "versionStartIncluding": "10.5.1.0"
            },
            {
              "criteria": "cpe:2.3:o:dell:networking_os10:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3825E399-818C-4EED-BE47-11A50D402A00",
              "versionEndExcluding": "10.5.2.8",
              "versionStartIncluding": "10.5.2.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}