← KEV catalog
CISA known exploited vulnerability

CVE-2021-1498

Cisco HyperFlex HX Data Platform Command Injection Vulnerability

SOURCE FACT

Cisco · HyperFlex HX

Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2021-1498

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?