• Platformchevron right
  • Solutionschevron right
  • Modern NDRchevron right
  • Resourceschevron right
  • Companychevron right

DETECTION OVERVIEW

Cisco HyperFlex HX Exploit Attempt - CVE-2021-1497

Risk Factors

Cisco HyperFlex HX hypervisors are not often exposed to the internet, but an unauthenticated attacker with network access to a HyperFlex device can leverage attack tools such as Metasploit modules to exploit this vulnerability. An attacker can gain complete control of a hypervisor within a data center and pivot to attack other systems in an organization.

Kill Chain

Exploitation

Risk Score

83

Detection diagram
Next in Exploitation: Cisco HyperFlex HX Exploit Attempt - CVE-2021-1498

Attack Background

Operating System (OS) command injection (also known as shell injection) is a web security vulnerability that enables an attacker to run arbitrary, malicious OS commands on a server running vulnerable software or applications. The web-based management interface of Cisco HyperFlex HX software has a vulnerability in how it validates user input. An attacker sends a specially designed HTTP request with a malicious code injection to the victim, which runs the code with root privileges. After compromising the hypervisor, the attacker can compromise other parts of the hosting infrastructure.

Mitigation Options

Upgrade to Cisco HyperFlex HX Release 4.0(2e) or 4.5(2a)

MITRE ATT&CK ID

What else can RevealX do for you?