Vulnerability Description
Dell Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an information disclosure vulnerability. A remote, unauthenticated attacker could potentially exploit this vulnerability by reverse engineering to retrieve sensitive information and access the REST API with admin privileges.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Smartfabric Os10 | >= 10.5.1.0, < 10.5.1.11 |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/kbdoc/en-us/000202971/dsa-2022-135-dell-emc-smartfaVendor Advisory
- https://www.dell.com/support/kbdoc/en-us/000202971/dsa-2022-135-dell-emc-smartfaVendor Advisory
FAQ
What is CVE-2022-29089?
CVE-2022-29089 is a vulnerability with a CVSS score of 6.4 (MEDIUM). Dell Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an information disclosure vulnerability. A remote, unauthenticated attacker could potentially exploit ...
How severe is CVE-2022-29089?
CVE-2022-29089 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-29089?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Smartfabric Os10.