VYPR
Unrated severityNVD Advisory· Published Nov 20, 2021· Updated Sep 17, 2024

CVE-2021-36310

CVE-2021-36310

Description

Dell Networking OS10 API service in multiple versions has uncontrolled resource consumption, allowing a high-privileged API user to cause denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Dell Networking OS10 API service in multiple versions has uncontrolled resource consumption, allowing a high-privileged API user to cause denial of service.

Vulnerability

Dell Networking OS10 versions 10.4.3.x, 10.5.0.x, 10.5.1.x, and 10.5.2.x contain an uncontrolled resource consumption flaw in its API service [1]. The vulnerability exists in the RESTCONF API, which is enabled by default in these versions. A high-privileged API user can trigger excessive resource consumption, leading to denial of service.

Exploitation

An attacker must have high-privileged access to the API service, meaning they need valid credentials with administrative privileges. The exploit does not require user interaction or specific network position beyond network access to the API endpoint. By sending crafted API requests that consume excessive system resources (e.g., memory or CPU), the attacker can exhaust available resources.

Impact

Successful exploitation results in denial of service (availability impact) on the affected OS10 system. The CVSS v3.1 base score is 4.9 (AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H) [1]. No impact to confidentiality or integrity is noted; the availability of the API service and potentially the entire system may be degraded or made unavailable.

Mitigation

Dell has released a security update (DSA-2021-189) that addresses this vulnerability [1]. Affected users should update to OS10 versions after October 2021, which contain the fix. No workaround has been published. The vulnerability is not listed on the CISA KEV as of this writing.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Dell/Dell Networking OS10llm-fuzzy2 versions
    10.4.3.x, 10.5.0.x, 10.5.1.x, 10.5.2.x+ 1 more
    • (no CPE)range: 10.4.3.x, 10.5.0.x, 10.5.1.x, 10.5.2.x
    • (no CPE)range: unspecified

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.