Executive brief
A command injection vulnerability in the web-based management interface of Cisco HyperFlex HX allows unauthenticated, remote attackers to execute arbitrary commands on the device. The flaw is due to insufficient input validation, potentially allowing command execution with tomcat8 user privileges.
Affected products
- Cisco HyperFlex HX Data Platform < 4.0(2e), 4.5(x) < 4.5(2a)
Timeline
- 2021-05-05: disclosed: Initial Cisco advisory publication
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog