First published: Thu May 06 2021(Updated: )
Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.
Credit: ykramarz@cisco.com psirt@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco HyperFlex | ||
Cisco HyperFlex | =4.0\(2a\) | |
Cisco Hyperflex HX220c M5 | ||
Cisco HyperFlex HX220c All NVMe M5 | ||
Cisco HyperFlex HX220c Edge M5 Firmware | ||
Cisco HyperFlex HX220c M5 | ||
Cisco HyperFlex HX240c | ||
Cisco HyperFlex HX240c AF M5 | ||
Cisco Hyperflex HX240c | ||
All of | ||
Any of | ||
Cisco HyperFlex | <4.0\(2e\) | |
Cisco HyperFlex | >=4.5<4.5\(2a\) | |
Any of | ||
Cisco Hyperflex HX220c M5 | ||
Cisco HyperFlex HX220c All NVMe M5 | ||
Cisco HyperFlex HX220c Edge M5 Firmware | ||
Cisco HyperFlex HX220c M5 | ||
Cisco HyperFlex HX240c | ||
Cisco HyperFlex HX240c AF M5 | ||
Cisco Hyperflex HX240c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-1497 is a command injection vulnerability in the web-based management interface of Cisco HyperFlex HX.
CVE-2021-1497 allows an unauthenticated remote attacker to perform command injection attacks against an affected device.
CVE-2021-1497 has a severity rating of 9.8 (Critical).
Cisco HyperFlex HX Data Platform version 4.0(2a) is affected by CVE-2021-1497.
Apply the necessary updates and patches provided by Cisco to fix CVE-2021-1497.