← All CVEs

CVE-2021-1497

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2021-11-03Remediation due 2021-11-17

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

9.8
CVSS
99.9%
EPSS (exploit prob.)
100th
EPSS percentile
2021-05-06
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
ciscohyperflex_hx_data_platform< 4.0\(2e\)
ciscohyperflex_hx_data_platform>= 4.5, < 4.5\(2a\)
ciscohyperflex_hx220c_af_m5all versions
ciscohyperflex_hx220c_all_nvme_m5all versions
ciscohyperflex_hx220c_edge_m5all versions
ciscohyperflex_hx220c_m5all versions
ciscohyperflex_hx240call versions
ciscohyperflex_hx240c_af_m5all versions
ciscohyperflex_hx240c_m5all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-1497