Cisco fixes risky flaws in HyperFlex and Prime infrastructure
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-15380 | A vulnerability in the cluster service manager of Cisco HyperFlex Software could allow an unauthenticated, adjacent attacker to execute commands as the root use A vulnerability in the cluster service manager of Cisco HyperFlex Software could allow an unauthenticated, adjacent attacker to execute commands as the root user. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by connecting to the cluster service manager and injecting commands into the bound process. A successful exploit could allow the attacker to run commands on the affected host as the root user. This vulnerability affects Cisco HyperFlex Software releases prior to 3.5(2a). NVD description · AI analysis pending | 8.8 | 1% |
| — | ||
| CVE-2019-1659 | A vulnerability in the Identity Services Engine (ISE) integration feature of Cisco Prime Infrastructure (PI) could allow an unauthenticated, remote attacker to A vulnerability in the Identity Services Engine (ISE) integration feature of Cisco Prime Infrastructure (PI) could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack against the Secure Sockets Layer (SSL) tunnel established between ISE and PI. The vulnerability is due to improper validation of the server SSL certificate when establishing the SSL tunnel with ISE. An attacker could exploit this vulnerability by using a crafted SSL certificate and could then intercept communications between the ISE and PI. A successful exploit could allow the attacker to view and alter potentially sensitive information that the ISE maintains about clients that are connected to the network. This vulnerability affects Cisco Prime Infrastructure Software Releases 2.2 through 3.4.0 when the PI server is integrated with ISE, which is disabled by default. NVD description · AI analysis pending | 7.4 | <1% |
| — | ||
| CVE-2019-1662 | A vulnerability in the Quality of Voice Reporting (QOVR) service of Cisco Prime Collaboration Assurance (PCA) Software could allow an unauthenticated, remote at A vulnerability in the Quality of Voice Reporting (QOVR) service of Cisco Prime Collaboration Assurance (PCA) Software could allow an unauthenticated, remote attacker to access the system as a valid user. The vulnerability is due to insufficient authentication controls. An attacker could exploit this vulnerability by connecting to the QOVR service with a valid username. A successful exploit could allow the attacker to perform actions with the privileges of the user that is used for access. This vulnerability affects Cisco PCA Software Releases prior to 12.1 SP2. NVD description · AI analysis pending | 9.1 | 2% |
| — | ||
| CVE-2019-1664 | A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in the cluster. A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in the cluster. The vulnerability is due to insufficient authentication controls. An attacker could exploit this vulnerability by connecting to the hxterm service as a non-privileged, local user. A successful exploit could allow the attacker to gain root access to all member nodes of the HyperFlex cluster. This vulnerability affects Cisco HyperFlex Software Releases prior to 3.5(2a). NVD description · AI analysis pending | 7.8 | <1% |
| — |
Full article306 words · extracted from helpnetsecurity.com · click to collapse
Cisco has released another batch of fixes for many of its products, including HyperFlex, Prime infrastructure, WebEx, and Firepower devices.

Fixed HyperFlex bugs
Five of the patched vulnerabilities affect Cisco HyperFlex Software, software running on Cisco HyperFlex HX-Series data center nodes.
Two of them are high risk security holes:
- CVE-2018-15380 could allow an unauthenticated, adjacent attacker to run commands on the affected host as the root user
- CVE-2019-1664 could allow an unauthenticated, local attacker to gain root access to all nodes of the HyperFlex cluster.
The remaining three flaws are less serious and mostly allow attackers to access/retrieve potentially sensitive information.
The remaining fixes
Among the other risky bugs squashed are CVE-2019-1659, a certificate validation vulnerability in Cisco Prime Infrastructure that could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack against the Secure Sockets Layer (SSL) tunnel established between the Identity Services Engine (ISE) and Prime Infrastructure (PI), and CVE-2019-1662, a vulnerability in the Quality of Voice Reporting service of Cisco Prime Collaboration Assurance Software could allow an unauthenticated, remote attacker to access the system as a valid user.
“An attacker could exploit [CVE-2019-1659] by using a crafted SSL certificate and could then intercept communications between the ISE and PI. A successful exploit could allow the attacker to view and alter potentially sensitive information that the ISE maintains about clients that are connected to the network,” Cisco explained.
Also important to note that the recently revealed RunC container escape bug has, so far, been found to affect only the Cisco Container Platform and Cisco Defense Orchestrator (though fixes are yet to be pushed out).
Many other products have been confirmed to not be vulnerable, and others are still under investigation.
All the released security advisories can be found here. Cisco says that none of the plugged holes are under active exploitation.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2019/02/21/cisco-hyperflex-flaws/