Vulnerability record · CVE-2021-1497 · published 6 May 2021
CVE-2021-1497: Cisco HyperFlex HX web management interface OS command injection
Cisco · Hyperflex Hx Data Platform
The web-based management interface of Cisco HyperFlex HX contains an OS command injection flaw (CWE-78) that lets an unauthenticated, remote attacker run commands on the affected device. With a CVSS 3.1 base score of 9.8 and a network-reachable, no-privilege vector, this is a full compromise of the appliance. It matters because HyperFlex HX is infrastructure management software, so a single unauthenticated request can hand over control of the platform.
Description
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote command injection with a 9.8 CVSS score, KEV listing, near-certain EPSS probability, and a public exploit reference make this an urgent patch-first item.
What it is
The web-based management interface of Cisco HyperFlex HX contains an OS command injection flaw (CWE-78) that lets an unauthenticated, remote attacker run commands on the affected device. With a CVSS 3.1 base score of 9.8 and a network-reachable, no-privilege vector, this is a full compromise of the appliance. It matters because HyperFlex HX is infrastructure management software, so a single unauthenticated request can hand over control of the platform.
Impact
An attacker gains arbitrary command execution with the privileges of the web interface process, which on an appliance of this type typically means full control of the host. That enables data theft, configuration tampering, and use of the device as a foothold into the surrounding environment.
Attack surface
Reached over the network through the HyperFlex HX web-based management interface; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required. Any internet- or management-network-exposed instance of that interface is directly reachable.
Exploitation
CVE-2021-1497 is listed in CISA KEV (added 2021-11-03) and has an EPSS 30-day probability of 0.99928 (99.97th percentile), and a public exploit reference is tagged Exploit on Packet Storm. CISA records no known ransomware campaign use.
What to do
- Apply the Cisco HyperFlex HX updates referenced in the vendor advisory cisco-sa-hyperflex-rce-TjjNrkpR, meeting the KEV due date of 2021-11-17.
- Restrict access to the HyperFlex HX web management interface to trusted management networks; do not expose it to the internet.
- Place the management interface behind a firewall or jump host and require VPN for administrative access.
- If patching cannot be completed immediately, isolate affected HyperFlex HX systems from untrusted networks and monitor them closely.
- Verify no unauthorized changes to appliance configuration or credentials after exposure.
Detection
- Inspect web server and application logs on HyperFlex HX for requests to the management interface containing shell metacharacters or command-like strings.
- Monitor for unexpected child processes spawned by the web management service, especially shell interpreters.
- Alert on outbound connections from HyperFlex HX management hosts to unfamiliar external addresses.
- Review authentication and access logs for management interface requests from unexpected source IPs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-1497 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/162976/Cisco-HyperFlex-HX-Data-Platform-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hyperflex-rce-TjjNrkpR | Vendor Advisory |
| http://packetstormsecurity.com/files/162976/Cisco-HyperFlex-HX-Data-Platform-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hyperflex-rce-TjjNrkpR | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-1497 | US Government Resource |
Track CVE-2021-1497 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-1497), CISA KEV, FIRST EPSS (scores of 2026-09-17). This page is refreshed as NVD updates the record.