CVE-2021-1498: Cisco HyperFlex HX Data Platform Command Injection Vulnerability
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Other sources
Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Cisco HyperFlex HX vulnerability?
The vulnerability ID for this Cisco HyperFlex HX vulnerability is CVE-2021-1498.
What is the title of this vulnerability?
The title of this vulnerability is Cisco HyperFlex HX Data Platform Command Injection Vulnerability.
What is the severity of CVE-2021-1498?
CVE-2021-1498 is rated with a severity score of 9.8 (critical).
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by performing command injection attacks against the web-based management interface of Cisco HyperFlex HX.
Is authentication required to exploit CVE-2021-1498?
No, authentication is not required to exploit CVE-2021-1498.