GPU VulnDB

Database/Firmware, BMC & network fabric

Dell Enterprise SONiC OS (information disclosure): An authenticated user can extract sensitive information

CVE-2021-36309Firmware, BMC & network fabriccurated

Impact

An authenticated user can extract sensitive information from Enterprise SONiC 3.3.0 and earlier. On a switch, 'sensitive information' generally means credentials for the things the switch talks to — TACACS/RADIUS secrets, SNMP communities, image-server logins — so the impact propagates outward from the device.

Who can reach it

Authenticated user with system access on the switch.

What to do

NOS image upgrade plus reboot, then rotate every shared secret configured on the switch. The rotation is the expensive part on a fleet that shares TACACS keys across all devices.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.