VYPR
Unrated severityNVD Advisory· Published Nov 20, 2021· Updated Sep 16, 2024

CVE-2021-36320

CVE-2021-36320

Description

Dell Networking X-Series firmware <3.0.1.9 and PowerEdge VRTX Switch Module <2.0.0.83 allow unauthenticated remote attackers to hijack webserver sessions by forging session IDs.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Dell Networking X-Series firmware <3.0.1.9 and PowerEdge VRTX Switch Module <2.0.0.83 allow unauthenticated remote attackers to hijack webserver sessions by forging session IDs.

Vulnerability

A session ID forgery vulnerability exists in Dell Networking X-Series firmware versions before 3.0.1.9 and Dell PowerEdge VRTX Switch Module firmware versions before 2.0.0.83 [1]. The webserver fails to properly validate the authenticity of session identifiers, allowing an attacker to bypass authentication by supplying a crafted session ID [1]. No special configuration or privilege is required to reach the vulnerable code path.

Exploitation

An unauthenticated remote attacker can exploit this flaw by intercepting or guessing a valid session ID, or by forging a session ID that the webserver accepts without validation [1]. The attacker must be able to send HTTP requests to the webserver. No user interaction is required beyond the victim having an active session, and the attacker may leverage network access to inject the forged session ID [1].

Impact

Successful exploitation results in session hijacking, giving the attacker unauthorized access to the webserver with the privileges of the hijacked session [1]. This can lead to full compromise of the affected device, including disclosure of sensitive information, modification of configuration, or disruption of operations. The CVSSv3.1 score is 7.5 (High) with a vector of AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating high confidentiality, integrity, and availability impact [1].

Mitigation

Dell has released firmware version 3.0.1.9 for Networking X-Series and version 2.0.0.83 for PowerEdge VRTX Switch Module to address this vulnerability [1]. Users should upgrade to the fixed versions. No workaround is mentioned in the available references [1]. The CVE is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog at the time of publication.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.