ZeroHour

CVE-2021-1497

KEV PoC niche

Root Command Injection in Cisco HyperFlex HX Installer Virtual Machine

CISA: Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

CVE-2021-1497 is a command injection flaw (CWE-78) in the Cisco HyperFlex HX Installer Virtual Machine, caused by insufficient validation of input processed by the installer VM. An attacker who can reach the affected installer VM can submit crafted input that causes arbitrary operating system commands to run with root privileges, giving full control of the appliance. Only organizations that have deployed the Cisco HyperFlex HX Installer Virtual Machine, typically as part of standing up or managing a HyperFlex hyperconverged cluster, are affected. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2021-11-03, indicating it is being exploited in the wild, and its EPSS score of 99.9% (100th percentile) implies a very high likelihood of exploitation attempts within 30 days. No public proof-of-concept is known, and CVSS scoring is not yet available.

What to do: Apply updates to the HyperFlex HX Installer Virtual Machine per Cisco's vendor instructions, as required by the CISA KEV catalog. Check whether the installer VM is still deployed (including on internal management networks), restrict network access to it from untrusted sources, and decommission it if it is no longer needed.

Affected
Cisco HyperFlex HX Installer Virtual Machine
Estimated exposure
nichelikely thousands of deployments at most, with only a subset internet-exposed (unknown exact count) — HyperFlex is a small share of the hyperconverged infrastructure market, the installer VM is deployed per cluster rollout and often decommissioned or kept on internal management networks afterward, so the affected installed base and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CISA Known Exploited Vulnerability
Affected
Cisco HyperFlex HX
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
hyperflex hx data platform
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news