9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected (2)
Products: Cisco: Hyperflex Hx Data Platform
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.0\(2e\) |
| Running on/with | Platform Versions |
|---|---|
Cisco Hyperflex Hx220c Af M5 | All versions |
Cisco Hyperflex Hx220c All Nvme M5 | All versions |
Cisco Hyperflex Hx220c Edge M5 | All versions |
Cisco Hyperflex Hx220c M5 | All versions |
Cisco Hyperflex Hx240c | All versions |
Cisco Hyperflex Hx240c Af M5 | All versions |
Cisco Hyperflex Hx240c M5 | All versions |
Related CWEs
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
References (5)
Source: psirt@cisco.com
ExploitThird Party AdvisoryVDB Entry
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.