Junglewise Threat Intelligence

CVE-2021-1498: Cisco HyperFlex HX Data Platform Command Injection Vulnerability

CVE-2021-1498 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Vendors: Cisco.

Executive brief

A command injection vulnerability in the web-based management interface of Cisco HyperFlex HX allows unauthenticated, remote attackers to execute arbitrary commands on the device. The flaw is due to insufficient input validation, potentially allowing command execution with tomcat8 user privileges.

Affected products

  • Cisco HyperFlex HX Data Platform < 4.0(2e), 4.5(x) < 4.5(2a)

Timeline

  • 2021-05-05: disclosed: Initial Cisco advisory publication
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats