Cisco
Cisco Hyperflex HX Data Platform: vulnerabilidades y CVE
Cisco Hyperflex HX Data Platform tiene 15 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses0
Críticas2
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-1497 | Crítica (9.8) | 100% | ⚠ Explotación activa | 6 may 2021 | Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information… |
| CVE-2021-1498 | Crítica (9.8) | 100% | ⚠ Explotación activa | 6 may 2021 | Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-20263 | Media (6.1) | 0.58% | — | 6 sept 2023 | A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper… |
| CVE-2021-1499 | Media (5.3) | 80% | — | 6 may 2021 | A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to upload files to an affected device. This vulnerability is due to missing… |
| CVE-2021-1498 | Crítica (9.8) | 100% | ⚠ Explotación activa | 6 may 2021 | Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information… |
| CVE-2021-1497 | Crítica (9.8) | 100% | ⚠ Explotación activa | 6 may 2021 | Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information… |
| CVE-2019-1958 | Alta (8.8) | 0.60% | — | 8 ago 2019 | A vulnerability in the web-based management interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The… |
| CVE-2019-1667 | Baja (3.3) | 0.17% | — | 21 feb 2019 | A vulnerability in the Graphite interface of Cisco HyperFlex software could allow an authenticated, local attacker to write arbitrary data to the Graphite interface. The vulnerability is due to insufficient… |
| CVE-2019-1666 | Media (5.3) | 2.2% | — | 21 feb 2019 | A vulnerability in the Graphite service of Cisco HyperFlex software could allow an unauthenticated, remote attacker to retrieve data from the Graphite service. The vulnerability is due to insufficient authentication… |
| CVE-2019-1665 | Media (6.1) | 1.1% | — | 21 feb 2019 | A vulnerability in the web-based management interface of Cisco HyperFlex software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management… |
| CVE-2019-1664 | Alta (7.8) | 0.33% | — | 21 feb 2019 | A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in the cluster. The vulnerability is due to insufficient authentication… |
| CVE-2018-15380 | Alta (8.8) | 1.1% | — | 20 feb 2019 | A vulnerability in the cluster service manager of Cisco HyperFlex Software could allow an unauthenticated, adjacent attacker to execute commands as the root user. The vulnerability is due to insufficient input… |
| CVE-2018-15429 | Media (5.3) | 1.1% | — | 5 oct 2018 | A vulnerability in the web-based UI of Cisco HyperFlex HX Data Platform Software could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability is due to a lack… |
| CVE-2018-15423 | Media (4.7) | 0.92% | — | 5 oct 2018 | A vulnerability in the web UI of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vulnerability is due to insufficient input… |
| CVE-2018-15407 | Media (5.5) | 0.29% | — | 5 oct 2018 | A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to read sensitive information. The vulnerability is due to insufficient cleanup of installation files.… |
| CVE-2018-15382 | Alta (8.6) | 1.3% | — | 5 oct 2018 | A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to generate valid, signed session tokens. The vulnerability is due to a static signing key that is present in all Cisco… |
| CVE-2017-12315 | Media (6) | 0.33% | — | 16 nov 2017 | A vulnerability in system logging when replication is being configured with the Cisco HyperFlex System could allow an authenticated, local attacker to view sensitive information that should be restricted in the system… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.