DSA-2021-017: Dell Networking Security Update for a Weak Password Encryption Vulnerability
Resumen: Dell Networking X-Series remediation is available for a weak password encryption vulnerability that may be exploited by malicious users to compromise the affected system.
Este artículo se aplica a
Este artículo no se aplica a
Este artículo no está vinculado a ningún producto específico.
No se identifican todas las versiones del producto en este artículo.
Impacto
High
Detalles
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2021-21507 | Dell Networking X-Series firmware versions prior to 3.0.1.8 and Dell PowerEdge VRTX firmware versions prior to 2.0.0.82 contain a Weak Password Encryption Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable system with privileges of the compromised account. | 8.8 | CVSS:3.1(AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) |
For information regarding the VRTX remediation, see KB article 185252: DSA-2020-080: Dell PowerEdge VRTX Security Update for a Weak Password Encryption Vulnerability
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2021-21507 | Dell Networking X-Series firmware versions prior to 3.0.1.8 and Dell PowerEdge VRTX firmware versions prior to 2.0.0.82 contain a Weak Password Encryption Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable system with privileges of the compromised account. | 8.8 | CVSS:3.1(AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) |
For information regarding the VRTX remediation, see KB article 185252: DSA-2020-080: Dell PowerEdge VRTX Security Update for a Weak Password Encryption Vulnerability
Corrección y productos afectados
| CVE Addressed | Product | Affected Version | Updated Version | Link to Update |
| CVE-2021-21507 | Dell Networking X-Series firmware | Versions prior to 3.0.1.2 |
3.0.1.8 | Link to X1000 Update Link to X4012 Update |
| CVE Addressed | Product | Affected Version | Updated Version | Link to Update |
| CVE-2021-21507 | Dell Networking X-Series firmware | Versions prior to 3.0.1.2 |
3.0.1.8 | Link to X1000 Update Link to X4012 Update |
Historial de revisiones
| Revision | Date | Description |
| 1.0 | 2021-04-14 | Initial Release |
| 1.1 | 2021-06-09 | Acknowledgement Update |
Reconocimientos
Dell Technologies would like to thank Ken Pyle for his contributions.
Información relacionada
Descargo de responsabilidad
Productos afectados
X SeriesProductos
Networking, Product Security InformationPropiedades del artículo
Número del artículo: 000185250
Tipo de artículo: Dell Security Advisory
Última modificación: 18 sept 2025
Encuentre respuestas a sus preguntas de otros usuarios de Dell
Servicios de soporte
Compruebe si el dispositivo está cubierto por los servicios de soporte.