SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-1499

A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to upload files to an affected device.

MEDIUM 5.3EPSS 80.4%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 80.4%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to upload files to an affected device. This vulnerability is due to missing authentication for the upload function. An attacker could exploit this vulnerability by sending a specific HTTP request to an affected device. A successful exploit could allow the attacker to upload files to the affected device with the permissions of the tomcat8 user.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
80.43% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-306
Affected
cisco/hyperflex hx data platform
Source
psirt@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.