Junglewise Threat Intelligence

CVE-2021-1497: Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability

CVE-2021-1497 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Vendors: Cisco.

Executive brief

A command injection vulnerability in the web-based management interface of Cisco HyperFlex HX allows unauthenticated, remote attackers to execute arbitrary commands as root. The flaw is due to insufficient input validation within the installer virtual machine.

Affected products

  • Cisco HyperFlex HX Data Platform < 4.0(2e), 4.5(1a) to < 4.5(2a)
  • Cisco HyperFlex HX Installer Virtual Machine

Timeline

  • 2021-05-06: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-05-05: advisory: Cisco Security Advisory published

Related threats