CVE-2021-1498KEV · OVERDUECWE-78

Cisco HyperFlex HX Command Injection Vulnerabilities

Critical · published May 6, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it critical at 9.8. It is confirmed in active exploitation. It sits in the 100.0th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
9.8
EPSS
100%
Percentile
100.0
In the wild
Confirmed
What it is

🚨 A remote attacker can perform command injection attacks with zero authentication on Cisco HyperFlex HX devices – that's like leaving your front door wide open and inviting trouble! 🔥 Picture a restaurant where anyone can just walk into the kitchen and start changing the menu. This is similar to how these vulnerabilities let attackers send harmful commands directly to the management interface without any checks. An attacker could potentially take full control of the affected device, leading to data theft, unauthorized access, or even complete system compromise. This is absolutely devastating for any organization relying on Cisco HyperFlex!

Put simply

Picture a restaurant where anyone can just walk into the kitchen and start changing the menu. This is similar to how these vulnerabilities let attackers send harmful commands directly to the management interface without any checks. This vulnerability allows unauthenticated remote attackers to execute arbitrary commands on the system through the web-based management interface, exploiting multiple flaws in the software's security.

What to do

An attacker could potentially take full control of the affected device, leading to data theft, unauthorized access, or even complete system compromise. This is absolutely devastating for any organization relying on Cisco HyperFlex! Immediate action is crucial! Upgrade your Cisco HyperFlex HX to the patched version as soon as possible to close this loophole. Ensure that access controls are enabled and properly configured to mitigate any further risk. You've got this! Follow these steps and your systems will be secure in no time. 🛡️

The record
Technical detail
CVSS v3.1
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.99999 · 100.0th percentile
Weakness
CWE-78 · Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Published
2021-05-06T12:41Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 06 MAY 12:41Z
    Cisco HyperFlex HX Command Injection Vulnerabilities
    cvelistv5