CRITICAL

CVE-2021-1497

Cisco Hyperflex Hx Data Platform 2021-05-06 CVSS v3.1
CVSS
9.8
KEV

Description

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

Summary dbcve.org

Multiple command injection vulnerabilities exist in the web-based management interface of Cisco HyperFlex HX. An unauthenticated, remote attacker can execute arbitrary operating system commands on the affected device by injecting malicious commands through the web interface parameters.

Mitigation

Apply Cisco's vendor patches for CVE-2021-1497. If patches are unavailable, restrict network access to the management interface to reduce exposure.

Proof of Concept

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

99.93%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE