VYPR
Unrated severityNVD Advisory· Published Nov 20, 2021· Updated Sep 16, 2024

CVE-2021-36319

CVE-2021-36319

Description

Dell Networking OS10 10.4.3.x, 10.5.0.x and 10.5.1.x allow a low-privileged authenticated user to access SNMP authentication failure logs, exposing sensitive information.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Dell Networking OS10 10.4.3.x, 10.5.0.x and 10.5.1.x allow a low-privileged authenticated user to access SNMP authentication failure logs, exposing sensitive information.

Vulnerability

Dell Networking OS10 versions 10.4.3.x, 10.5.0.x, and 10.5.1.x contain an information exposure vulnerability in the SNMP service. A low-privileged authenticated user with local access can view SNMP authentication failure messages, which may contain sensitive data such as community strings or other authentication details [1].

Exploitation

The attacker must already have a valid low-privileged account on the affected OS10 system and local access to the device. No special privileges beyond a standard authenticated session are required. By querying the SNMP authentication failure logs, the attacker can retrieve messages that were not properly restricted [1].

Impact

Successful exploitation results in unauthorized disclosure of sensitive information contained in SNMP authentication failure messages. This has a low confidentiality impact as per CVSS 3.1 base score 3.3 [1]. The attacker does not gain the ability to modify data or disrupt services; the scope remains unchanged.

Mitigation

Dell has released a fix as part of the October 2021 security update. Customers should upgrade to OS10 versions 10.4.3.x or 10.5.x that include the patch [1]. If upgrading is not immediately possible, restrict local access to trusted administrators and monitor SNMP logs for unauthorized access attempts.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Dell/Dell Networking OS10llm-fuzzy2 versions
    = 10.4.3.x, 10.5.0.x, 10.5.1.x+ 1 more
    • (no CPE)range: = 10.4.3.x, 10.5.0.x, 10.5.1.x
    • (no CPE)range: unspecified

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.