EXPOSURES › CVE-2021-1498
CVE-2021-1498
HIGH ⌖ ON CISA KEV · EXPLOITEDCisco HyperFlex HX installer VM had insufficient input validation allowing command execution as tomcat8 user.
The HyperFlex HX Installer Virtual Machine lacked proper input validation, enabling attackers to execute arbitrary commands as the tomcat8 user. DIB organizations must ensure installer components are rigorously validated and patched, as this flaw represents a remote code execution vulnerability that could compromise the entire hyperconverged infrastructure.
Shame score — Insufficient input validation in a critical installer component allowed remote code execution, indicating a fundamental flaw in the deployment artifact that could have been mitigated with proper validation practices.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |