← Vulnerability feed

Vulnerability record · CVE-2021-1497 · published 6 May 2021

CVE-2021-1497: Cisco HyperFlex HX web management interface OS command injection

Cisco · Hyperflex Hx Data Platform

The web-based management interface of Cisco HyperFlex HX contains an OS command injection flaw (CWE-78) that lets an unauthenticated, remote attacker run commands on the affected device. With a CVSS 3.1 base score of 9.8 and a network-reachable, no-privilege vector, this is a full compromise of the appliance. It matters because HyperFlex HX is infrastructure management software, so a single unauthenticated request can hand over control of the platform.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 EPSS 100% · top 0.1% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated remote command injection with a 9.8 CVSS score, KEV listing, near-certain EPSS probability, and a public exploit reference make this an urgent patch-first item.

What it is

The web-based management interface of Cisco HyperFlex HX contains an OS command injection flaw (CWE-78) that lets an unauthenticated, remote attacker run commands on the affected device. With a CVSS 3.1 base score of 9.8 and a network-reachable, no-privilege vector, this is a full compromise of the appliance. It matters because HyperFlex HX is infrastructure management software, so a single unauthenticated request can hand over control of the platform.

Impact

An attacker gains arbitrary command execution with the privileges of the web interface process, which on an appliance of this type typically means full control of the host. That enables data theft, configuration tampering, and use of the device as a foothold into the surrounding environment.

Attack surface

Reached over the network through the HyperFlex HX web-based management interface; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required. Any internet- or management-network-exposed instance of that interface is directly reachable.

Exploitation

CVE-2021-1497 is listed in CISA KEV (added 2021-11-03) and has an EPSS 30-day probability of 0.99928 (99.97th percentile), and a public exploit reference is tagged Exploit on Packet Storm. CISA records no known ransomware campaign use.

What to do

  • Apply the Cisco HyperFlex HX updates referenced in the vendor advisory cisco-sa-hyperflex-rce-TjjNrkpR, meeting the KEV due date of 2021-11-17.
  • Restrict access to the HyperFlex HX web management interface to trusted management networks; do not expose it to the internet.
  • Place the management interface behind a firewall or jump host and require VPN for administrative access.
  • If patching cannot be completed immediately, isolate affected HyperFlex HX systems from untrusted networks and monitor them closely.
  • Verify no unauthorized changes to appliance configuration or credentials after exposure.

Detection

  • Inspect web server and application logs on HyperFlex HX for requests to the management interface containing shell metacharacters or command-like strings.
  • Monitor for unexpected child processes spawned by the web management service, especially shell interpreters.
  • Alert on outbound connections from HyperFlex HX management hosts to unfamiliar external addresses.
  • Review authentication and access logs for management interface requests from unexpected source IPs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-1497 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-1497 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-1498Cisco HyperFlex HX web management interface command injectionThe web-based management interface of Cisco HyperFlex HX contains command injection flaws (CWE-78/CWE-77) that let an unauthenticated, remote attacke…KEVEPSS 100%analysed8.8CVE-2019-1958Cisco hyperflex hx data platform cross-site request forgery vulnerabilityA vulnerability in the web-based management interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to conduct a cross-…EPSS 0.60%8.8CVE-2018-15380Cisco hyperflex hx data platform os command injection vulnerabilityA vulnerability in the cluster service manager of Cisco HyperFlex Software could allow an unauthenticated, adjacent attacker to execute commands as t…EPSS 1.1%8.6CVE-2018-15382Cisco hyperflex hx data platform vulnerabilityA vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to generate valid, signed session tokens. The vulnerabili…EPSS 1.3%7.8CVE-2019-1664Cisco hyperflex hx data platform improper access control vulnerabilityA vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in …EPSS 0.33%6.1CVE-2023-20263Cisco hyperflex hx data platform open redirect vulnerabilityA vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to redirect…EPSS 0.58%6.1CVE-2019-1665Cisco hyperflex hx data platform cross-site scripting vulnerabilityA vulnerability in the web-based management interface of Cisco HyperFlex software could allow an unauthenticated, remote attacker to conduct a cross-…EPSS 1.1%6.0CVE-2017-12315Cisco hyperflex hx data platform information exposure vulnerabilityA vulnerability in system logging when replication is being configured with the Cisco HyperFlex System could allow an authenticated, local attacker t…EPSS 0.33%

Source: NIST National Vulnerability Database (record CVE-2021-1497), CISA KEV, FIRST EPSS (scores of 2026-09-17). This page is refreshed as NVD updates the record.