CRITICAL
CVE-2021-1497
CVSS
9.8
KEV
Description
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Summary dbcve.org
Multiple command injection vulnerabilities exist in the web-based management interface of Cisco HyperFlex HX. An unauthenticated, remote attacker can execute arbitrary operating system commands on the affected device by injecting malicious commands through the web interface parameters.
Mitigation
Apply Cisco's vendor patches for CVE-2021-1497. If patches are unavailable, restrict network access to the management interface to reduce exposure.
Weakness (CWE)
CWE-78
OS Command Injection
EPSS Score
99.93%
Probability of exploitation in next 30 days
100th percentile
References
http://packetstormsecurity.com/files/162976/Cisco-HyperFlex-HX-Data-Platform-Command-Execution.html
Exploit, Third Party Advisory, VDB Entry
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hyperflex-rce-TjjNrkpR
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-1497
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.