CVE-2021-1498

Description

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
94.206

Associated Vulnerability

VulnerabilityOS Platform
Cisco HyperFlex HX Command Injection Vulnerabilities For Cisco HyperFlex HX-SeriesNCM
Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability (CVE-2021-1498)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1705210Security Update for Cisco HyperFlex HX-Series 4.5(2a)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234