Vulnerability Description
Dell Networking X-Series firmware versions prior to 3.0.1.8 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary host header values to poison the web-cache or trigger redirections.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | X1008P Firmware | < 3.0.1.8 |
| Dell | X1008P | - |
| Dell | X1018P Firmware | < 3.0.1.8 |
| Dell | X1018P | - |
| Dell | X1026P Firmware | < 3.0.1.8 |
| Dell | X1026P | - |
| Dell | X1052P Firmware | < 3.0.1.8 |
| Dell | X1052P | - |
| Dell | X4012 Firmware | < 3.0.1.8 |
| Dell | X4012 | - |
| Dell | X1008 Firmware | < 3.0.1.8 |
| Dell | X1008 | - |
| Dell | X1018 Firmware | < 3.0.1.8 |
| Dell | X1018 | - |
| Dell | X1026 Firmware | < 3.0.1.8 |
| Dell | X1026 | - |
| Dell | X1052 Firmware | < 3.0.1.8 |
| Dell | X1052 | - |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/kbdoc/en-us/000193230/dsa-2021-191-dell-networking-PatchVendor Advisory
- https://www.dell.com/support/kbdoc/en-us/000193230/dsa-2021-191-dell-networking-PatchVendor Advisory
FAQ
What is CVE-2021-36322?
CVE-2021-36322 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Dell Networking X-Series firmware versions prior to 3.0.1.8 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arb...
How severe is CVE-2021-36322?
CVE-2021-36322 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-36322?
Check the references section above for vendor advisories and patch information. Affected products include: Dell X1008P Firmware, Dell X1008P, Dell X1018P Firmware, Dell X1018P, Dell X1026P Firmware.