• Platformchevron right
  • Solutionschevron right
  • Modern NDRchevron right
  • Resourceschevron right
  • Companychevron right

DETECTION OVERVIEW

Cisco HyperFlex HX Exploit Attempt - CVE-2021-1498

Risk Factors

Cisco HyperFlex HX hypervisors are not often exposed to the internet, but an unauthenticated attacker with network access to a HyperFlex device can leverage attack tools such as Metasploit modules to exploit this vulnerability. An attacker can gain complete control of a hypervisor within a data center and pivot to attack other systems in an organization.

Kill Chain

Exploitation

Risk Score

83

Detection diagram
Next in Exploitation: Cisco IOS XE Exploit - CVE-2023-20198

Attack Background

Operating System (OS) command injection (also known as shell injection) is a vulnerability that enables an attacker to run arbitrary, malicious OS commands on a server running vulnerable software. The web-based management interface of Cisco HyperFlex HX has a vulnerability in how it validates user input. An attacker can send a malicious HTTP request that results in remote code execution. After compromising the hypervisor, the attacker can further attack other parts of the hosting infrastructure.

Mitigation Options

Upgrade to Cisco HyperFlex HX Release 4.0(2e) or 4.5(2a)

MITRE ATT&CK ID

What else can RevealX do for you?