CVE-2021-21507
moderate-risk
Published 2021-04-30
Dell EMC Networking X-Series firmware versions prior to 3.0.1.8 and Dell EMC PowerEdge VRTX Switch Module firmware versions prior to 2.0.0.82 contain a Weak Password Encryption Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable system with privileges of the compromised account.
Do I need to act?
-
0.12% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.8/10
High
ADJACENT_NETWORK
/ LOW complexity
Affected Products (11)
X1008P Firmware
X1018P Firmware
X1026P Firmware
X1052P Firmware
X4012 Firmware
X1008 Firmware
X1018 Firmware
X1026 Firmware
X1052 Firmware
Affected Vendors
References (2)
43
/ 100
moderate-risk
Severity
27/34 · High
Exploitability
0/34 · Minimal
Exposure
16/34 · Moderate