ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-1468
+4 in the same advisory: …1505 …1508 …1275 …1506
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application. For more information about these vulnerabilities, see the Details section of this advisory.

NVD description · AI analysis pending
9.8
group max
2%
  • cisco catalyst sd-wan manager
  • cisco sd-wan vmanage
CVE-2021-1498
+1 in the same advisory: …1497
Command Injection in Cisco HyperFlex HX Data Platform / Installer VM

CVE-2021-1498 is an OS command injection flaw (CWE-78) caused by insufficient input validation in the Cisco HyperFlex HX Installer Virtual Machine, part of the HyperFlex HX Data Platform. An attacker who can reach the vulnerable interface can trigger the flaw and execute arbitrary commands on the affected device with the privileges of the tomcat8 user. Successful exploitation allows the attacker to run commands on the underlying system, potentially facilitating further compromise of the HyperFlex cluster. Organizations running Cisco HyperFlex HX deployments with the affected HX Installer VM are exposed. The vulnerability is listed in the CISA Known Exploited Vulnerabilities catalog as of 2021-11-03, indicating exploitation in the wild, and EPSS assigns it a 100.0% probability of exploitation within 30 days (100th percentile).

Do: Apply the updated HyperFlex HX Data Platform software per Cisco's security advisory, as required by the CISA KEV catalog (due date per KEV policy for federal agencies). Restrict access to the HX Installer VM web interface to trusted management networks while patching. Review affected systems for signs of unexpected command execution by the tomcat8 user, given confirmed in-the-wild exploitation.

9.8100% KEV PoC
  • Cisco HyperFlex HX (HX Data Platform / HX Installer Virtual Machine)
moderate≈1,000–10,000 HX Installer VMs deployed worldwide, with far fewer directly reachable from the internet
CVE-2021-21984
VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point.

VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point. A malicious actor with network access may exploit this issue causing unauthorised remote code execution on vRealize Business for Cloud Virtual Appliance.

NVD description · AI analysis pending
9.82%
  • vmware vrealize business for cloud
Full article419 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananMay 06, 2021

Networking equipment major Cisco has rolled out software updates to address multiple critical vulnerabilities impacting HyperFlex HX and SD-WAN vManage Software that could allow an attacker to perform command injection attacks, execute arbitrary code, and gain access to sensitive information.

In a series of advisories published on May 5, the company said there are no workarounds that remediate the issues.

The HyperFlex HX command injection vulnerabilities, tracked as CVE-2021-1497 and CVE-2021-1498 (CVSS scores 9.8), affect all Cisco devices running HyperFlex HX software versions 4.0, 4.5, and those prior to 4.0. Arising due to insufficient validation of user-supplied input in the web-based management interface of Cisco HyperFlex HX Data Platform, the flaws could enable an unauthenticated, remote attacker to perform a command injection attack against a vulnerable device.

"An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface," the company said in its alert. "A successful exploit could allow the attacker to execute arbitrary commands" either as a root or tomcat8 user.

Cisco also squashed five glitches affecting SD-WAN vManage Software (CVE-2021-1275, CVE-2021-1468, CVE-2021-1505, CVE-2021-1506, and CVE-2021-1508) that could permit an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application.

Nikita Abramov and Mikhail Klyuchnikov of Positive Technologies have been credited with reporting the HyperFlex HX flaws, whereas four of the SD-WAN vManage bugs were identified during internal security testing, with CVE-2021-1275 uncovered during the resolution of a Cisco Technical Assistance Center (TAC) support case.

While there is no evidence of malicious use of the vulnerabilities in the wild, it's recommended that users upgrade to the latest version to mitigate the risk associated with the flaws.

VMware Fixes Critical vRealize Business for Cloud Bug

It's not just Cisco. VMware on Wednesday released patches to fix a critical severity flaw in vRealize Business for Cloud 7.6 that enables unauthenticated attackers to execute malicious code on vulnerable servers remotely.

The remote code execution flaw (CVE-2021-21984, CVSS score: 9.8) stems from an unauthorized VAMI endpoint, resulting in a scenario that could cause an adversary with network access to run unauthorized code on the appliance. Affected customers can rectify the issue by installing the security patch ISO file.

Vmware credited Egor Dimitrenko of Positive Technologies for reporting the vulnerability.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/05/critical-flaws-hit-cisco-sd-wan-vmanage.html