CRITICAL
CVE-2021-1498
CVSS
9.8
KEV
Description
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Summary dbcve.org
Multiple command injection vulnerabilities in the web-based management interface of Cisco HyperFlex HX allow unauthenticated remote attackers to execute arbitrary operating system commands on affected devices due to insufficient input validation.
Mitigation
Apply Cisco-provided patches for HyperFlex HX; until patched, restrict network access to the management interface to trusted sources only.
Weakness (CWE)
CWE-78
OS Command Injection
CWE-77
Command Injection
EPSS Score
100%
Probability of exploitation in next 30 days
100th percentile
References
http://packetstormsecurity.com/files/162976/Cisco-HyperFlex-HX-Data-Platform-Command-Execution.html
Exploit, Third Party Advisory, VDB Entry
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hyperflex-rce-TjjNrkpR
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-1498
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.