CVE-2021-1497
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-78
מוצרים מושפעים
cisco: hyperflex hx data platform; cisco: hyperflex hx220c af m5; cisco: hyperflex hx220c all nvme m5; cisco: hyperflex hx220c edge m5; cisco: hyperflex hx220c m5; cisco: hyperflex hx240c; cisco: hyperflex hx240c af m5; cisco: hyperflex hx240c m5
קישורים
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa… Vendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa… Vendor Advisory
- http://packetstormsecurity.com/files/162976/Cisco-HyperFlex-HX-Data-Platform-C… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/162976/Cisco-HyperFlex-HX-Data-Platform-C… ExploitThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource