← KEV catalog
CISA known exploited vulnerability

CVE-2021-1497

Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability

SOURCE FACT

Cisco · HyperFlex HX

Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2021-1497

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?