Executive brief
A command injection vulnerability in the web-based management interface of Cisco HyperFlex HX allows unauthenticated, remote attackers to execute arbitrary commands as root. The flaw is due to insufficient input validation within the installer virtual machine.
Affected products
- Cisco HyperFlex HX Data Platform < 4.0(2e), 4.5(1a) to < 4.5(2a)
- Cisco HyperFlex HX Installer Virtual Machine
Timeline
- 2021-05-06: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-05-05: advisory: Cisco Security Advisory published