CVE-2021-1497
KEV PoC nicheRoot Command Injection in Cisco HyperFlex HX Installer Virtual Machine
CISA: Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability
CVE-2021-1497 is a command injection flaw (CWE-78) in the Cisco HyperFlex HX Installer Virtual Machine, caused by insufficient validation of input processed by the installer VM. An attacker who can reach the affected installer VM can submit crafted input that causes arbitrary operating system commands to run with root privileges, giving full control of the appliance. Only organizations that have deployed the Cisco HyperFlex HX Installer Virtual Machine, typically as part of standing up or managing a HyperFlex hyperconverged cluster, are affected. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2021-11-03, indicating it is being exploited in the wild, and its EPSS score of 99.9% (100th percentile) implies a very high likelihood of exploitation attempts within 30 days. No public proof-of-concept is known, and CVSS scoring is not yet available.
What to do: Apply updates to the HyperFlex HX Installer Virtual Machine per Cisco's vendor instructions, as required by the CISA KEV catalog. Check whether the installer VM is still deployed (including on internal management networks), restrict network access to it from untrusted sources, and decommission it if it is no longer needed.
| Cisco HyperFlex HX Installer Virtual Machine | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
- Affected
- Cisco HyperFlex HX
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- hyperflex hx data platform
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H