CVE-2021-1497 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 99.9% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2021-11-17.
Description
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 99.93% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | yes — remediate by 2021-11-17 |
| Public exploit | none known |
| Published | 2021-05-06 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability |
|---|---|
| Added | 2021-11-03 |
| Due | 2021-11-17 |
| Vendor / product | Cisco / HyperFlex HX |
| Ransomware use | none reported |
Affected (8)
| Vendor | Product |
|---|---|
| cisco | hyperflex hx data platform |
| cisco | hyperflex hx220c af m5 |
| cisco | hyperflex hx220c all nvme m5 |
| cisco | hyperflex hx220c edge m5 |
| cisco | hyperflex hx220c m5 |
| cisco | hyperflex hx240c |
| cisco | hyperflex hx240c af m5 |
| cisco | hyperflex hx240c m5 |
References
- http://packetstormsecurity.com/files/162976/Cisco-HyperFlex-HX-Data-Platform-Command-Execution.html
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hyperflex-rce-TjjNrkpR
- http://packetstormsecurity.com/files/162976/Cisco-HyperFlex-HX-Data-Platform-Command-Execution.html
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hyperflex-rce-TjjNrkpR
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-1497
→ the Explorer · watch your stack · NVD