// For flags

CVE-2019-12621

Cisco HyperFlex Static SSL Key Vulnerability

Severity Score

7.4
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack. The vulnerability is due to insufficient key management. An attacker could exploit this vulnerability by obtaining a specific encryption key for the cluster. A successful exploit could allow the attacker to perform a man-in-the-middle attack against other nodes in the cluster.

Una vulnerabilidad en el software Cisco HyperFlex podría permitir que un atacante remoto no autenticado realice un ataque man-in-the-middle. La vulnerabilidad se debe a una gestión de claves insuficiente. Un atacante podría aprovechar esta vulnerabilidad al obtener una clave de cifrado específica para el clúster. Una explotación exitosa podría permitir al atacante realizar un ataque de hombre en el medio contra otros nodos en el clúster.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-06-04 CVE Reserved
  • 2019-08-21 CVE Published
  • 2023-05-08 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-320: Key Management Errors
  • CWE-327: Use of a Broken or Risky Cryptographic Algorithm
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Hyperflex Hx220c M5 Firmware
Search vendor "Cisco" for product "Hyperflex Hx220c M5 Firmware"
3.0\(1a\)
Search vendor "Cisco" for product "Hyperflex Hx220c M5 Firmware" and version "3.0\(1a\)"
-
Affected
in Cisco
Search vendor "Cisco"
Hyperflex Hx220c M5
Search vendor "Cisco" for product "Hyperflex Hx220c M5"
--
Safe
Cisco
Search vendor "Cisco"
Hyperflex Hx220c M5 Firmware
Search vendor "Cisco" for product "Hyperflex Hx220c M5 Firmware"
3.5\(2a\)
Search vendor "Cisco" for product "Hyperflex Hx220c M5 Firmware" and version "3.5\(2a\)"
-
Affected
in Cisco
Search vendor "Cisco"
Hyperflex Hx220c M5
Search vendor "Cisco" for product "Hyperflex Hx220c M5"
--
Safe
Cisco
Search vendor "Cisco"
Hyperflex Hx240c M5 Firmware
Search vendor "Cisco" for product "Hyperflex Hx240c M5 Firmware"
3.0\(1a\)
Search vendor "Cisco" for product "Hyperflex Hx240c M5 Firmware" and version "3.0\(1a\)"
-
Affected
in Cisco
Search vendor "Cisco"
Hyperflex Hx240c M5
Search vendor "Cisco" for product "Hyperflex Hx240c M5"
--
Safe
Cisco
Search vendor "Cisco"
Hyperflex Hx240c M5 Firmware
Search vendor "Cisco" for product "Hyperflex Hx240c M5 Firmware"
3.5\(2a\)
Search vendor "Cisco" for product "Hyperflex Hx240c M5 Firmware" and version "3.5\(2a\)"
-
Affected
in Cisco
Search vendor "Cisco"
Hyperflex Hx240c M5
Search vendor "Cisco" for product "Hyperflex Hx240c M5"
--
Safe
Cisco
Search vendor "Cisco"
Hyperflex Hx220c Af M5 Firmware
Search vendor "Cisco" for product "Hyperflex Hx220c Af M5 Firmware"
3.0\(1a\)
Search vendor "Cisco" for product "Hyperflex Hx220c Af M5 Firmware" and version "3.0\(1a\)"
-
Affected
in Cisco
Search vendor "Cisco"
Hyperflex Hx220c Af M5
Search vendor "Cisco" for product "Hyperflex Hx220c Af M5"
--
Safe
Cisco
Search vendor "Cisco"
Hyperflex Hx220c Af M5 Firmware
Search vendor "Cisco" for product "Hyperflex Hx220c Af M5 Firmware"
3.5\(2a\)
Search vendor "Cisco" for product "Hyperflex Hx220c Af M5 Firmware" and version "3.5\(2a\)"
-
Affected
in Cisco
Search vendor "Cisco"
Hyperflex Hx220c Af M5
Search vendor "Cisco" for product "Hyperflex Hx220c Af M5"
--
Safe
Cisco
Search vendor "Cisco"
Hyperflex Hx240c Af M5 Firmware
Search vendor "Cisco" for product "Hyperflex Hx240c Af M5 Firmware"
3.0\(1a\)
Search vendor "Cisco" for product "Hyperflex Hx240c Af M5 Firmware" and version "3.0\(1a\)"
-
Affected
in Cisco
Search vendor "Cisco"
Hyperflex Hx240c Af M5
Search vendor "Cisco" for product "Hyperflex Hx240c Af M5"
--
Safe
Cisco
Search vendor "Cisco"
Hyperflex Hx240c Af M5 Firmware
Search vendor "Cisco" for product "Hyperflex Hx240c Af M5 Firmware"
3.5\(2a\)
Search vendor "Cisco" for product "Hyperflex Hx240c Af M5 Firmware" and version "3.5\(2a\)"
-
Affected
in Cisco
Search vendor "Cisco"
Hyperflex Hx240c Af M5
Search vendor "Cisco" for product "Hyperflex Hx240c Af M5"
--
Safe
Cisco
Search vendor "Cisco"
Hyperflex Hx220c Edge M5 Firmware
Search vendor "Cisco" for product "Hyperflex Hx220c Edge M5 Firmware"
3.0\(1a\)
Search vendor "Cisco" for product "Hyperflex Hx220c Edge M5 Firmware" and version "3.0\(1a\)"
-
Affected
in Cisco
Search vendor "Cisco"
Hyperflex Hx220c Edge M5
Search vendor "Cisco" for product "Hyperflex Hx220c Edge M5"
--
Safe
Cisco
Search vendor "Cisco"
Hyperflex Hx220c Edge M5 Firmware
Search vendor "Cisco" for product "Hyperflex Hx220c Edge M5 Firmware"
3.5\(2a\)
Search vendor "Cisco" for product "Hyperflex Hx220c Edge M5 Firmware" and version "3.5\(2a\)"
-
Affected
in Cisco
Search vendor "Cisco"
Hyperflex Hx220c Edge M5
Search vendor "Cisco" for product "Hyperflex Hx220c Edge M5"
--
Safe