ZeroHour

CVE-2021-1498

KEV PoC moderate

Command Injection in Cisco HyperFlex HX Data Platform / Installer VM

CISA: Cisco HyperFlex HX Data Platform Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

CVE-2021-1498 is an OS command injection flaw (CWE-78) caused by insufficient input validation in the Cisco HyperFlex HX Installer Virtual Machine, part of the HyperFlex HX Data Platform. An attacker who can reach the vulnerable interface can trigger the flaw and execute arbitrary commands on the affected device with the privileges of the tomcat8 user. Successful exploitation allows the attacker to run commands on the underlying system, potentially facilitating further compromise of the HyperFlex cluster. Organizations running Cisco HyperFlex HX deployments with the affected HX Installer VM are exposed. The vulnerability is listed in the CISA Known Exploited Vulnerabilities catalog as of 2021-11-03, indicating exploitation in the wild, and EPSS assigns it a 100.0% probability of exploitation within 30 days (100th percentile).

What to do: Apply the updated HyperFlex HX Data Platform software per Cisco's security advisory, as required by the CISA KEV catalog (due date per KEV policy for federal agencies). Restrict access to the HX Installer VM web interface to trusted management networks while patching. Review affected systems for signs of unexpected command execution by the tomcat8 user, given confirmed in-the-wild exploitation.

Affected
Cisco HyperFlex HX (HX Data Platform / HX Installer Virtual Machine)
Estimated exposure
moderate≈1,000–10,000 HX Installer VMs deployed worldwide, with far fewer directly reachable from the internet — Cisco HyperFlex is an enterprise hyperconverged infrastructure product with one HX Installer VM per cluster, so an order-of-magnitude estimate in the low thousands of deployments follows from typical HCI adoption, and the installer…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CISA Known Exploited Vulnerability
Affected
Cisco HyperFlex HX
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
hyperflex hx data platform
Weakness
CWE-78, CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news