Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Nov 17, 2021

CVE-2021-1497

High
CVSS 9.8EPSS 94.4%CISA KEVPoC Available
Cisco/HyperFlex HX

Description

Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.

CVSS Score

9.8/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS — Exploit Probability

94.4%

Higher than 100.0% of all CVEs

Weakness Classification (CWE)

CWE-78OS Command InjectionMITRE

Required Action

https://nvd.nist.gov/vuln/detail/CVE-2021-1497

Risk Assessment

CRITICAL
In CISA KEV
Known exploit
Critical CVSS
High EPSS

Details

Severity
High
CVSS
9.8
EPSS
94.4%
CWE
CWE-78
Exploit
POC
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Nov 3, 2021

Added to KEV

Nov 3, 2021

Remediation Due

Nov 17, 2021

Affected Product

Cisco

HyperFlex HX

View all Cisco CVEs