CISA Known Exploited Vulnerability

CVE-2021-1497

Cisco · HyperFlex HX

Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability

Date added
BOD 22-01 due date
CWE CWE-78
Ransomware Unknown

CISA description

Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.

Required action

Apply updates per vendor instructions.