← Vulnerability feed

Vulnerability record · CVE-2021-1498 · published 6 May 2021

CVE-2021-1498: Cisco HyperFlex HX web management interface command injection

Cisco · Hyperflex Hx Data Platform

The web-based management interface of Cisco HyperFlex HX contains command injection flaws (CWE-78/CWE-77) that let an unauthenticated, remote attacker run commands on the affected device. With a CVSS 3.1 score of 9.8 and no privileges or user interaction required, this is a full-compromise class issue for any exposed management interface.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 EPSS 100% · top 0.1% CWE-78 · OS command injectionCWE-77 · Command injection
9.8CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, confirmed KEV listing, near-maximum EPSS, and public exploit code make this an urgent, actively targeted flaw.

What it is

The web-based management interface of Cisco HyperFlex HX contains command injection flaws (CWE-78/CWE-77) that let an unauthenticated, remote attacker run commands on the affected device. With a CVSS 3.1 score of 9.8 and no privileges or user interaction required, this is a full-compromise class issue for any exposed management interface.

Impact

An attacker gains arbitrary command execution on the HyperFlex HX appliance, which can lead to full control of the device and any data or credentials it holds.

Attack surface

Reached over the network through the web-based management interface (AV:N, PR:N, UI:N). No authentication or user interaction is needed, so any internet- or network-exposed management endpoint is directly at risk.

Exploitation

CISA added it to KEV on 2021-11-03 with a 2021-11-17 remediation due date, and EPSS is 0.99999 (99.991st percentile); public exploit code is referenced via Packet Storm. No ransomware campaign use is documented in this record.

What to do

  • Apply the Cisco HyperFlex HX updates referenced in the vendor advisory cisco-sa-hyperflex-rce-TjjNrkpR as the first action.
  • Remove the HyperFlex HX management interface from direct internet exposure and restrict it to a trusted management network or VPN.
  • Enforce network access controls and firewall rules limiting who can reach the management interface.
  • Monitor for and investigate any signs of compromise on HyperFlex HX appliances, since exploitation is known and widespread.
  • Track the CISA KEV due date to confirm remediation is completed.

Detection

  • Review web server and appliance logs for unusual requests to the HyperFlex HX management interface, especially patterns consistent with command injection.
  • Alert on unexpected or suspicious child processes spawned by the web management service on HyperFlex HX hosts.
  • Monitor outbound connections from HyperFlex HX appliances to unknown external hosts for signs of post-exploitation activity.
  • Correlate network access logs to identify any external or untrusted sources reaching the management interface.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-1498 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Cisco HyperFlex HX Data Platform Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-1498 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-1497Cisco HyperFlex HX web management interface OS command injectionThe web-based management interface of Cisco HyperFlex HX contains an OS command injection flaw (CWE-78) that lets an unauthenticated, remote attacker…KEVEPSS 100%analysed8.8CVE-2019-1958Cisco hyperflex hx data platform cross-site request forgery vulnerabilityA vulnerability in the web-based management interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to conduct a cross-…EPSS 0.60%8.8CVE-2018-15380Cisco hyperflex hx data platform os command injection vulnerabilityA vulnerability in the cluster service manager of Cisco HyperFlex Software could allow an unauthenticated, adjacent attacker to execute commands as t…EPSS 1.1%8.6CVE-2018-15382Cisco hyperflex hx data platform vulnerabilityA vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to generate valid, signed session tokens. The vulnerabili…EPSS 1.3%7.8CVE-2019-1664Cisco hyperflex hx data platform improper access control vulnerabilityA vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in …EPSS 0.33%6.1CVE-2023-20263Cisco hyperflex hx data platform open redirect vulnerabilityA vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to redirect…EPSS 0.58%6.1CVE-2019-1665Cisco hyperflex hx data platform cross-site scripting vulnerabilityA vulnerability in the web-based management interface of Cisco HyperFlex software could allow an unauthenticated, remote attacker to conduct a cross-…EPSS 1.1%6.0CVE-2017-12315Cisco hyperflex hx data platform information exposure vulnerabilityA vulnerability in system logging when replication is being configured with the Cisco HyperFlex System could allow an authenticated, local attacker t…EPSS 0.33%

Source: NIST National Vulnerability Database (record CVE-2021-1498), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.