Vulnerability Description
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Hyperflex Hx Data Platform | < 4.0\(2e\) |
| Cisco | Hyperflex Hx220C Af M5 | - |
| Cisco | Hyperflex Hx220C All Nvme M5 | - |
| Cisco | Hyperflex Hx220C Edge M5 | - |
| Cisco | Hyperflex Hx220C M5 | - |
| Cisco | Hyperflex Hx240C | - |
| Cisco | Hyperflex Hx240C Af M5 | - |
| Cisco | Hyperflex Hx240C M5 | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/162976/Cisco-HyperFlex-HX-Data-Platform-ComExploitThird Party AdvisoryVDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hVendor Advisory
- http://packetstormsecurity.com/files/162976/Cisco-HyperFlex-HX-Data-Platform-ComExploitThird Party AdvisoryVDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-US Government Resource
FAQ
What is CVE-2021-1497?
CVE-2021-1497 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. Fo...
How severe is CVE-2021-1497?
CVE-2021-1497 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-1497?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Hyperflex Hx Data Platform, Cisco Hyperflex Hx220C Af M5, Cisco Hyperflex Hx220C All Nvme M5, Cisco Hyperflex Hx220C Edge M5, Cisco Hyperflex Hx220C M5.