CVE-2021-1497
Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
YesDecision
Descriptions
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Múltiples vulnerabilidades en la interfaz de administración basada en web de Cisco HyperFlex HX, podrían permitir a un atacante remoto no autenticado llevar a cabo ataques de inyección de comandos contra un dispositivo afectado. Para obtener más información sobre estas vulnerabilidades, consulte la sección Detalles de este aviso
Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.
CVSS Scores
SSVC
- Decision:Act
Timeline
- 2020-11-13 CVE Reserved
- 2021-05-06 CVE Published
- 2021-11-03 Exploited in Wild
- 2021-11-17 KEV Due Date
- 2024-11-08 CVE Updated
- 2024-11-08 First Exploit
- 2024-11-13 EPSS Updated
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (4)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Hyperflex Hx Data Platform Search vendor "Cisco" for product "Hyperflex Hx Data Platform" | 4.0\(2a\) Search vendor "Cisco" for product "Hyperflex Hx Data Platform" and version "4.0\(2a\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Hyperflex Hx220c Af M5 Search vendor "Cisco" for product "Hyperflex Hx220c Af M5" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Hyperflex Hx Data Platform Search vendor "Cisco" for product "Hyperflex Hx Data Platform" | 4.0\(2a\) Search vendor "Cisco" for product "Hyperflex Hx Data Platform" and version "4.0\(2a\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Hyperflex Hx220c All Nvme M5 Search vendor "Cisco" for product "Hyperflex Hx220c All Nvme M5" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Hyperflex Hx Data Platform Search vendor "Cisco" for product "Hyperflex Hx Data Platform" | 4.0\(2a\) Search vendor "Cisco" for product "Hyperflex Hx Data Platform" and version "4.0\(2a\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Hyperflex Hx220c Edge M5 Search vendor "Cisco" for product "Hyperflex Hx220c Edge M5" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Hyperflex Hx Data Platform Search vendor "Cisco" for product "Hyperflex Hx Data Platform" | 4.0\(2a\) Search vendor "Cisco" for product "Hyperflex Hx Data Platform" and version "4.0\(2a\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Hyperflex Hx220c M5 Search vendor "Cisco" for product "Hyperflex Hx220c M5" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Hyperflex Hx Data Platform Search vendor "Cisco" for product "Hyperflex Hx Data Platform" | 4.0\(2a\) Search vendor "Cisco" for product "Hyperflex Hx Data Platform" and version "4.0\(2a\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Hyperflex Hx240c Search vendor "Cisco" for product "Hyperflex Hx240c" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Hyperflex Hx Data Platform Search vendor "Cisco" for product "Hyperflex Hx Data Platform" | 4.0\(2a\) Search vendor "Cisco" for product "Hyperflex Hx Data Platform" and version "4.0\(2a\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Hyperflex Hx240c Af M5 Search vendor "Cisco" for product "Hyperflex Hx240c Af M5" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Hyperflex Hx Data Platform Search vendor "Cisco" for product "Hyperflex Hx Data Platform" | 4.0\(2a\) Search vendor "Cisco" for product "Hyperflex Hx Data Platform" and version "4.0\(2a\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Hyperflex Hx240c M5 Search vendor "Cisco" for product "Hyperflex Hx240c M5" | - | - |
Safe
|